For Active Directory to trust the server certificate, you must install the CA certificate chain for the certificate into the server hosting Active Directory. You must install the entire CA certificate chain, from the root CA to the issuing CA (the CA that issued the server certificate). For an on-premises CA, the root CA may be the issuing CA. You must install the CA certificate chain into Active Directory before you install the server certificate.
To install a CA certificate into Active Directory
- For an on-premises CA, obtain all CA certificates in the CA certificate chain using your on-premises CA tools. See the documentation for your on-premises CA for instructions.
- For Entrust PKI as a Service, download all CA certificates in the certificate chain:
Log in the Entrust Certificate Services interface.
Select Administration > PKIaaS Management.
A list of private CAs appear.For each CA in the TLS certificate chain (from the Issuing CA to the Root CA), select the CA and then click Download certificate.
- Double-click the CA certificate file.
The Certificate dialog box appears. - Click Install Certificate.
The Certificate Import Wizard appears. - The Welcome to the Certificate Import Wizard page appears.
- For Store Location, select Local Machine.
- Click Next.
- The Certificate Store page appears.
- Select Place all certificates in the following store.
- Click Browse.
The Select Certificate Store dialog box appears. - If the CA certificate is a root CA certificate, select Trusted Root Certification Authorities.
- If the CA certificate is a subordinate (intermediate) CA certificate, select Intermediate Certification Authorities.
- Click OK.
- Click Next.
- The Completing the Certificate Import Wizard page appears.
- Click OK.