Certificate practices using IdP with MS AD LDAP

David Bantz dabantz at alaska.edu
Mon Apr 22 18:29:47 EDT 2013


It must be fairly common for IdP deployments to depend upon LDAP from AD component of a Domain Controller.   I am inquiring about strategies for this dependency - specifically, the use of X.509 certificates for establishing encrypted communications between the IdP and AD LDAP.   

We're exploring a number of options in response to our Windows Server group recently determining they will exclusively use the internal Microsoft certificate generator and private CA for use within the Domain.  I am soliciting the experience of other institutions with similar deployments.  Do you:


a) Import the certificate for the Domain's private CA into the default root CA store for use by the IdP to enable ldaps?

b) Import the certificate for the Domain's private CA into an alternate location for java trusted CA?

In either case, how do you ensure that both the private CA and other well-known CAs have up-to-date certificates in that store?

c) Require the Domain to use a widely known trusted root CA such as the Comodo certificates available via InCommon?

d) Combine the use of the private CA internal to the Domain and use a different certificate signed by well-known trusted CA for the externally facing LDAP connection (which our Windows Server Group denotes as a "service certificate" rather than the more familiar "server certificate," a term I had not heard previously and would like to understand!)?

e) Configure the IdP and AD in a "trusted" or "secure" subnet and allow unencrypted ldap communication?

f) Some better alternative I didn't think of?

I will summarize responses to the list, so you can reply directly to dabantz at alaska.edu if you don't think your response needs to go directly to the entire list.

Thank you!

David Bantz
U Alaska IAM


More information about the users mailing list