Hi everyone,
First, thanks in advance for your time and responses.
I'm a little nieve on PKI. I'm configuring our Confluence server to authenticate users against AD over port 636. I've been reading this:
https://confluence.atlassian.com/adminjiraserver073/connecting-to-an-ldap-directory-861253200.html
But it doesn't quite hit the mark. We have our own PKI infrastructure- offline root, online intermediaries, etc. So my questions are:
- Wouldn't we just import the intermediary cert chain instead of individual AD servers?
- If we have multiple domain controllers supporting our domain, do we have to import the cert issued for each domain controller? Or just importing the cert for one suffices?
Or.... am I completely misunderstanding- which is quite possible!