In the Active Directory Domain Controller, install all certificates in the CA certificate chain as trusted root certificates.

To install the CA certificates in the Active Directory Domain Controller

  1. Log in to the server hosting Active Directory.
  2. Open the Group Policy Management administrative tool. Select Start > Windows Administrative Tools > Group Policy Management.
    The Group Policy Management dialog box appears.
  3. In the tree view, expand the Domain Controller you will modify.
  4. Right-click Default Domain Policy > Edit.
    The Group Policy Management Editor dialog box appears.
  5. In the tree view, expand Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies > Trusted Root Certification Authorities.
  6. Right-click Trusted Root Certification Authorities > Import.
  7. Select the Security Manager CA certificates or the CA certificates file you obtained earlier in Obtaining the CA certificates.