Would you like to learn how to install the Active Directory service and enable the LDAP over SSL feature on a computer runnin Windows server?In this tutorial, we are going to show you how enable the LDAP over SSL feature on a computer running Windows server.
• Windows 2012 R2
Hardware List:
The following section presents the list of equipment used to create this Windows tutorial.
Every piece of hardware listed above can be found at Amazon website.
Windows Playlist:
On this page, we offer quick access to a list of videos related to Windows installation.
Don’t forget to subscribe to our youtube channel named FKIT.
Windows Related Tutorial:
On this page, we offer quick access to a list of tutorials related to Windows.
Tutorial – Active Directory Installation on Windows
• IP – 192.168.15.10.
• Operacional System – Windows 2012 R2
• Hostname – TECH-DC01
• Active Directory Domain: TECH.LOCAL
If you already have an Active Directory domain, you may skip this part of the tutorial.
Open the Server Manager application.
Access the Manage menu and click on Add roles and features.
data:image/s3,"s3://crabby-images/628db/628db61212523b5e7f30210a1cf8fef05c87a7d7" alt="Windows 2012 add role Windows 2012 add role"
Access the Server role screen, select the Active Directory Domain Service and click on the Next button.
data:image/s3,"s3://crabby-images/51b69/51b69c9e3038f4f957461b16dec54d2e360c380a" alt="active directory installation active directory installation"
On the following screen, click on the Add features button.
data:image/s3,"s3://crabby-images/8f5f8/8f5f8b9b4d8f8090471f79d1ee4c0ab3411338fb" alt="active directory windows installation active directory windows installation"
Keep clicking on the Next button until you reach the last screen.
data:image/s3,"s3://crabby-images/f7c4d/f7c4d954c507af4de1db4b629c9c807784fb74d0" alt="windows install active directory windows install active directory"
On the confirmation screen, click on the Install button.
data:image/s3,"s3://crabby-images/e79b0/e79b092f8654da0a80bbe5548f5e77836f5f68a5" alt="active directory installation confirmation active directory installation confirmation"
Wait the Active directory installation to finish.
data:image/s3,"s3://crabby-images/cdc09/cdc0945b2e07487d8c96c40eb38cea0e7c0f907d" alt="active directory installation windows active directory installation windows"
Open the Server Manager application.
Click on the yellow flag menu and select the option to promote this server to a domain controller
data:image/s3,"s3://crabby-images/8fb29/8fb29ee4bde377f9d5b22c13a67ff1f1e58180f4" alt="active directory configuration active directory configuration"
Select the option to Add a new forest and enter a root domain name.
In our example, we created a new domain named: TECH.LOCAL.
data:image/s3,"s3://crabby-images/38241/382418c9f6c040aa706e19e487f0c3fddd181697" alt="deployment active directory deployment active directory"
Enter a password to secure the Active Directory restoration.
data:image/s3,"s3://crabby-images/be977/be977c6674d217ad8aeb186f8c3a44dab37bab02" alt="domain controller options domain controller options"
On the DNS options screen, click on the Next button.
data:image/s3,"s3://crabby-images/4df85/4df85658918bffe2208ffc86e9d825916897f9de" alt="active directory dns options active directory dns options"
Verify the Netbios name assigned to your domain and click on the Next button.
data:image/s3,"s3://crabby-images/42b52/42b52f005a96fc6adc4e9be4ee94dd2ae976a5e4" alt="ad netbios name ad netbios name"
Click on the Next button.
data:image/s3,"s3://crabby-images/f7a9f/f7a9f9f8998fc4ac7ff8b5c72b67ca4c9daabf3c" alt="active directory paths active directory paths"
Review your configuration options and click on the Next button.
data:image/s3,"s3://crabby-images/fce53/fce532c9e13469c86b75f243fa6bc7a20580dfd0" alt="active directory summary active directory summary"
On the Prerequisites Check screen, click on the Install button.
data:image/s3,"s3://crabby-images/5d265/5d2657393cfe64ec2d3487937e8cb7fb5763a3a0" alt="active directory prerequisites check active directory prerequisites check"
Wait the Active Directory Configuration to finish.
data:image/s3,"s3://crabby-images/278e8/278e8fce92c38e25378863b498a8f0f1200a2fd2" alt="active directory installation wizard active directory installation wizard"
After finishing the Active directory installation, the computer will restart automatically
You have finished the Active directory configuration on Windows server.
Tutorial – Testing the LDAP over SSL communication
We need to test if your domain controller is offering the LDAP over SSL service on port 636.
On the domain controller, access the start menu and search for the LDP application.
data:image/s3,"s3://crabby-images/88a55/88a55a77e022316ef8d2111ad86ad13d286dcab8" alt="Windows 2012 desktop Windows 2012 desktop"
First, let’s test if your domain controller is offering the LDAP service on port 389.
Access the Connection menu and select the Connect option.
data:image/s3,"s3://crabby-images/01de7/01de79f59d7ae6de371d3386ad8e9193f117ad21" alt="Windows LDP application Windows LDP application"
Try to connect to the localhost using the TCP port 389.
data:image/s3,"s3://crabby-images/7f844/7f844f383654c4382f508d7f6dbf499952371c77" alt="Windows ldp ldap connection Windows ldp ldap connection"
You should be able to connect to the LDAP service on the localhost port 389.
data:image/s3,"s3://crabby-images/9a463/9a4630b75f6736a323bfe06b950dab57871fb96c" alt="Windows ldap connection Ok Windows ldap connection Ok"
Now, we need to test if your domain controller is offering the LDAP over SSL service on port 636.
Open a new LDP application Window and try to connect to the localhost using the TCP port 636.
Select the SSL checkbox and click on the Ok button.
data:image/s3,"s3://crabby-images/8ec94/8ec943eac19f5e0105e6eb864cd8cb8d48a091c0" alt="Windows ldp ssl connection Windows ldp ssl connection"
If the system displays an error message, your domain controller is not offering the LDAPS service yet.
To solve this, we are going to install a Windows Certification authority on the next part of this tutorial.
data:image/s3,"s3://crabby-images/80885/8088545178d48ba2ac26bff017d1998612f91608" alt="ldp error 636 warning ldp error 636 warning"
If you were able to successfully connect to the localhost on port 636 using SSL encryption, you may skip the next part of this tutorial.
Tutorial – Certification Authority Installation on Windows
We need to install the Windows certification authority service.
The local certification authority will provide the domain controller with a certificate that will allow the LDAPS service to operate on the TCP port 636.
Open the Server Manager application.
Access the Manage menu and click on Add roles and features.
data:image/s3,"s3://crabby-images/628db/628db61212523b5e7f30210a1cf8fef05c87a7d7" alt="Windows 2012 add role Windows 2012 add role"
Access the Server role screen, select the Active Directory Certificate Services and click on the Next button.
data:image/s3,"s3://crabby-images/c9f6e/c9f6e910a6e2c004b75920bb2d17085359dc05e3" alt="windows certification authority installation windows certification authority installation"
On the following screen, click on the Add features button.
data:image/s3,"s3://crabby-images/ebdcf/ebdcff9ae6967095d9d71e52755de93aa9ddfad8" alt="active directory certificate service active directory certificate service"
Keep clicking on the Next button until you reach the role service screen.
Enable the option named Certification Authority and click on the Next button.
data:image/s3,"s3://crabby-images/e70d4/e70d4a146a9ad80a9a98e3e8c289a619bb6fec6e" alt="Windows server 2012 Certification authority install Windows server 2012 Certification authority install"
On the confirmation screen, click on the Install button.
data:image/s3,"s3://crabby-images/bbf49/bbf49f83fcd99f8f2e392ebc2d270698151661ab" alt="Windows ca confirmation screen Windows ca confirmation screen"
Wait the Certification Authority installation to finish.
data:image/s3,"s3://crabby-images/eda9a/eda9ab8ed4636ab504b5e11a35394204fd637568" alt="Windows 2012 R2 certification authority installation Windows 2012 R2 certification authority installation"
Open the Server Manager application.
Click on the yellow flag menu and select the option: Configure Active Directory Certificate Services
data:image/s3,"s3://crabby-images/31e28/31e2860876bdb440b62d1518e068fd2e8ceb1d69" alt="certification authority post deployment certification authority post deployment"
On the credentials screen, click on the Next button.
Select the Certification Authority option and click on the Next button.
data:image/s3,"s3://crabby-images/ad341/ad341b6f100877d9e1dec2bded251d2527ae84cc" alt="Windows certification authority role service Windows certification authority role service"
Select the Enterprise CA option and click on the Next button.
data:image/s3,"s3://crabby-images/478d6/478d6b1b9b455a73103c2ed7f5f0b1a1b4a8e72b" alt="windows enterprise ca windows enterprise ca"
Select the Create a new private key option and click on the Next button.
data:image/s3,"s3://crabby-images/ed1b8/ed1b86592c4139b960da330ea6f722b4805ada17" alt="windows ca new private key windows ca new private key"
Keep the default cryptography configuration and click on the Next button.
data:image/s3,"s3://crabby-images/602b4/602b4af9a781c85a7406566dc354414686c37958" alt="windows cryptography for ca windows cryptography for ca"
Set a common name to the Certification authority and click on the Next button.
In our example, we set the common name: TECH-CA
data:image/s3,"s3://crabby-images/3d336/3d336e9abea7bdd9425eb9d40ec00b0587262c49" alt="Windows CA name configuration Windows CA name configuration"
Set the Windows Certification authority validity period.
data:image/s3,"s3://crabby-images/d81a9/d81a93e495cadb1e244b279fd86743ad204722d0" alt="Windows CA validity period Windows CA validity period"
Keep the default Windows Certification authority database location.
data:image/s3,"s3://crabby-images/3c9fd/3c9fd7c099f2c57d7922fc15ae573c969a3cde35" alt="windows certificate database windows certificate database"
Verify the summary and click on the Configure button.
data:image/s3,"s3://crabby-images/72901/729017da320eab288caa90d769b57e5b347fc230" alt="Windows Ca installation summary Windows Ca installation summary"
Wait for the Windows server certification authority installation to finish.
data:image/s3,"s3://crabby-images/d9172/d9172fd9e73859c0aec5657959797a7ba0c41c36" alt="Windows cs authority results Windows cs authority results"
After finishing the certification authority installation, reboot your computer.
You have finished the Windows Certification authority installation.
Tutorial – Testing the LDAP over SSL Communication Again
We need to test if your domain controller is offering the LDAP over SSL service on port 636.
After finishing the Certification authority installation, wait 5 minutes and restart your domain controller.
During boot time, your domain controller will automatically request a server certificate from the local certification authority.
After getting the server certificate, your domain controller will start offering the LDAP service over SSL on the 636 port.
On the domain controller, access the start menu and search for the LDP application.
data:image/s3,"s3://crabby-images/88a55/88a55a77e022316ef8d2111ad86ad13d286dcab8" alt="Windows 2012 desktop Windows 2012 desktop"
Access the Connection menu and select the Connect option.
data:image/s3,"s3://crabby-images/01de7/01de79f59d7ae6de371d3386ad8e9193f117ad21" alt="Windows LDP application Windows LDP application"
Try to connect to the localhost using the TCP port 636.
Select the SSL checkbox and click on the Ok button.
data:image/s3,"s3://crabby-images/8ec94/8ec943eac19f5e0105e6eb864cd8cb8d48a091c0" alt="Windows ldp ssl connection Windows ldp ssl connection"
Try to connect to the localhost using the TCP port 636.
Select the SSL checkbox and click on the Ok button.
This time, you should be able to connect to the LDAP service on the localhost port 636.
data:image/s3,"s3://crabby-images/6478a/6478a6f2e7af80f078b839b16c47aaa4d8423e7d" alt="Windows ldaps connection Ok Windows ldaps connection Ok"
If you are not able to connect to port 636, reboot the computer again and wait 5 minutes more.
It may take sometime before your domain controller receives the certificate requested from the Certification Authority.