ManageEngine ADSelfService Plus – How to apply a wildcard cert ?
ADSelfService Plus by ManageEngine is a great tool. The instructions provided to configure SSL did not work for me, but I was able to figure it out doing the following:
You need a PFX File: Wild Card Cert for *.yourdomain.com (Yourdomain-WildCard.pfx) – This can be generated/ exported by IIS if you have a wildcard cert.
STEPS to apply and use Wildcard cert:
- Enable SSL in ADSelfService Plus.
- Click “Admin” tab –> Product Settings –> Connection.
- Enable “Enable SSL Port [https]” check-box -> click “Save” button.
- Stop ADSelfService Plus. (Start –> All Programs –> ADSelfService Plus –> Stop ADSelfService Plus) .
- Save the “.pfx” file under “C:\ManageEngine\ADSelfService Plus\confâ€, take a backup copy of server.xml file and then edit the “server.xml” file.
- Go to the bottom of server.xml file and edit connector tag and add the keystoreFile, keystorePass, keystoreType and save the file.
<Connector SSLEnabled="true" acceptCount="100" clientAuth="false" connectionTimeout="20000" debug="0" disableUploadTimeout="true" enableLookups="false" keystoreFile="./conf/YourDomain-WildCard.pfx" keystorePass="Private Key Password" keystoreType="PKCS12" maxSpareThreads="75" maxThreads="150" minSpareThreads="25" name="SSL" port="443" scheme="https" secure="true" sslProtocol="TLS"/>
- Start ADSelfService Plus or restart the server.
Hope this helps!
Author
Related Posts
Get all the domains controllers in the AD forest along with their current FSMO roles
In a large enterprise an admin would need to keep track of all the domains in a AD forest, the domain names,...
Read out all
Force synchronization for DFSR-replicated SYSVOL
One of my clients had a problem with processing GPO on client computers. Different computers applied different settings from the same GPO...
Get Inactive Users Report for the past 60 days in a multi domain environment
I had a request recently to provide an inactive user report for the past 60 days. Basically, find out which accounts have...
Get Primary, Secondary, Tertiary DNS values and more from Multiple Servers
Came across a unique request to get primary, secondary, and tertiary DNS values for multiple computers/servers across the domain. I started writing...
Fix Active Directory broken security inheritance problem
Ran into a situation at a client location where in Active Directory, the security permissions applied to an OU were not getting...
How to Fix: Attribute userAccountControl of DC is: 0x82020
When running a DCDiag at a customer site today I had the following error occur: [su_box title=”” box_color=”#f3f1cb” title_color=”#000000″ radius=”6″]Warning: Attribute userAccountControl...