Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Type of certificate required in SSM for AD connection

DaveW
New Contributor II
New Contributor II

Hello,

Can someone please inform me what certificate I need to import into SSM validate a LDAPS url for an AD connection.

My assumption is that SSM requires the root certificate of the CA that issued the server certificate to the AD Domain Controller placed into the SSM Certificate Management store, therefore it can validate and trust the server certificate. Is this correct?

There is no documentation that I can find that illustrates how SSM validates a certificate.

Thanks

 

4 REPLIES 4

dgandhi
All-Star
All-Star

Did you check below document?

https://docs.saviyntcloud.com/bundle/AD-v2021x/page/Content/Configuring-the-Integration-for-Importin...

https://docs.saviyntcloud.com/bundle/EIC-Admin-v2021x/page/Content/Chapter07-General-Administrator/C...

 

 

SSL Certificate

Specify the SSL certificates to secure the connection between IGA and the target application for encrypting the data shared between them.

You can use the user interface to map the SSL certificate with the connection. The certificates are stored in the EIC trust store. This was done outside of EIC in the previous releases. For more information, see  Certificate Management in the Enterprise Identity Cloud Administration Guide.

-

Yes, Saviynt recommends you to add SSL certficates.

Thanks,
Devang Gandhi
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.

Hey Devang,

Could you please let us know the exact type of certificate needed, who should it be issued to and what are the steps to generate the certificate from AD. The documents shared by you do not address these queries.

Thanks in advance.

Generating the certificate wont be responsibility of IDM team, you will just need to request the SSL cert for your AD domain from your AD team, once you get the cert, install that in Saviynt with above mentioned steps and you should be good.

 

Thanks,
Devang Gandhi
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.

DaveW
New Contributor II
New Contributor II

Hi,

The question I asked is about the SSL TYPE (i.e., Root, client, server) of certificate that the SSM certificate mgmt. store requires for a successful connection.

I believe only the Root cert from the issuing CA is required to validate the SSL cert on the domain controller.

In terms of your original answer to me, of course I went through the documentation, but as you can see from that documentation it just says 'SSL Cert', which is why I asked the question on the forum. And there are many types of SSL cert