> Source: [sk84620](https://support.checkpoint.com/results/sk/sk84620)

# sk84620 - How to configure Endpoint Security Server to connect to Domain Controller (DC) via LDAPS

| Property | Value |
|----------|-------|
| Solution ID | sk84620 |
| Date Created | 2012-09-12 |
| Last Modified | 2026-08-05 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

There are situations in which it is desired to configure the Endpoint Security Server to connect to a Domain Controller (DC) via LDAPS.

Proceed as follows:

*** ** * ** ***

**-1- Save the certificate to a file for import**
-------------------------------------------------

### **(1) First way**

1. To check what certificate is actually returned by AD server when connecting to it over port 636 use the command from server were you want configuration SSL scanner:  
   **cpopenssl s_client -connect \<host\>:\<port\> \| cpopenssl x509 -fingerprint** **Example:**   
   \[Expert@Primary_R81_10_B:0\]# *cpopenssl s_client -connect 192.168.236.191:636 \| cpopenssl* *x509 -fingerprint*   
   Can't use SSL_get_servername  
   depth=0 CN = WIN-6OMKORLP7NE.alex.domain  
   verify error:num=20:unable to get local issuer certificate  
   verify return:1  
   depth=0 CN = WIN-6OMKORLP7NE.alex.domain  
   verify error:num=21:unable to verify the first certificate  
   verify return:1  
   depth=0 CN = WIN-6OMKORLP7NE.alex.domain  
   verify return:1  
   SHA1 Fingerprint=88:DF:29:56:47:E7:D3:B9:39:46:76:8E:55:0B:0F:90:E7:A4:12:FF  
   -----BEGIN CERTIFICATE-----  
   MIIGGDCCBQCgAwIBAgITHQAAAAPZM4IG131+lQAAAAAAAzANBgkqhkiG9w0BAQsF  
   ADBQMRYwFAYKCZImiZPyLGQBGRYGZG9tYWluMRQwEgYKCZImiZPyLGQBGRYEYWxl  
   eDEgMB4GA1UEAxMXYWxleC1XSU4tNk9NS09STFA3TkUtQ0EwHhcNMjMwNDE4MTMy  
   NTU0WhcNMjQwNDE3MTMyNTU0WjAmMSQwIgYDVQQDExtXSU4tNk9NS09STFA3TkUu  
   YWxleC5kb21haW4wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCvL11N  
   +490huUohvfQ//j2k35XCHSr0E9v+zEmNUi3kfK9Qy2sYeVmdsz+jbCAkjqXygFC  
   EzXJL8MsyDIvCzWTtAB/J9qT9g9iXiWSmNpurHf4P7NaThIukOSs4ZBlfdiRYa7F  
   y3O+RVLEqS8vPr8JCDARuaIEIoylOG3b25LbyZID/sv2hmYldnGV2bas2efF7CXJ  
   7nSjrQf+l91KUTiM72lmoanW2FJSKTVmaGZ+HdgH7xqI5IlgFrXIrvTn5ZgDNyag  
   DgWgrSDnFe6fRhDsQ6tiq8aoIZ0Ar5s82QAW6uToaR1P1loGPmdFl+ntK2CBwzbK  
   M0/Wd/mSqmZL3WzPAgMBAAGjggMTMIIDDzAvBgkrBgEEAYI3FAIEIh4gAEQAbwBt  
   AGEAaQBuAEMAbwBuAHQAcgBvAGwAbABlAHIwHQYDVR0lBBYwFAYIKwYBBQUHAwIG  
   CCsGAQUFBwMBMA4GA1UdDwEB/wQEAwIFoDB4BgkqhkiG9w0BCQ8EazBpMA4GCCqG  
   SIb3DQMCAgIAgDAOBggqhkiG9w0DBAICAIAwCwYJYIZIAWUDBAEqMAsGCWCGSAFl  
   AwQBLTALBglghkgBZQMEAQIwCwYJYIZIAWUDBAEFMAcGBSsOAwIHMAoGCCqGSIb3  
   DQMHMEcGA1UdEQRAMD6gHwYJKwYBBAGCNxkBoBIEEOc/TYhY+oBIuWLircVieOCC  
   G1dJTi02T01LT1JMUDdORS5hbGV4LmRvbWFpbjAdBgNVHQ4EFgQU0dSneBlf8r0w  
   77AlSW/CinSVziwwHwYDVR0jBBgwFoAUYNr80uYoE0z6k4mHgahoQO9BJ0Mwgd0G  
   A1UdHwSB1TCB0jCBz6CBzKCByYaBxmxkYXA6Ly8vQ049YWxleC1XSU4tNk9NS09S  
   TFA3TkUtQ0EsQ049V0lOLTZPTUtPUkxQN05FLENOPUNEUCxDTj1QdWJsaWMlMjBL  
   ZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25maWd1cmF0aW9uLERDPWFs  
   ZXgsREM9ZG9tYWluP2NlcnRpZmljYXRlUmV2b2NhdGlvbkxpc3Q/YmFzZT9vYmpl  
   Y3RDbGFzcz1jUkxEaXN0cmlidXRpb25Qb2ludDCByQYIKwYBBQUHAQEEgbwwgbkw  
   gbYGCCsGAQUFBzAChoGpbGRhcDovLy9DTj1hbGV4LVdJTi02T01LT1JMUDdORS1D  
   QSxDTj1BSUEsQ049UHVibGljJTIwS2V5JTIwU2VydmljZXMsQ049U2VydmljZXMs  
   Q049Q29uZmlndXJhdGlvbixEQz1hbGV4LERDPWRvbWFpbj9jQUNlcnRpZmljYXRl  
   P2Jhc2U/b2JqZWN0Q2xhc3M9Y2VydGlmaWNhdGlvbkF1dGhvcml0eTANBgkqhkiG  
   9w0BAQsFAAOCAQEASt2qCEnvDhxJ2Au7XTdXESTy3+kqLd5Loeq19Yrv98uYRdkx  
   tATfsAR3o/tDolue0lbHbt97ttOCWP0HDuyLpq5lWXuSmXnCRFaRZ7auLmNdiFTz  
   di8VET3yaGL3s282tvzb5HZZY+cpo0/EdRHr8LGEadCabRnOImPgcPKEZzmS0zrk  
   0KZB3nKp5R/zPU4Y7Kq9zbs0aY1ZITXLfzAbs2fiLC1pJM6O2YTXJJ9pKGBkNsut  
   X72JvqR5j+la0E55piK6vuQHJ6abwTHQ4px0Pg6e5dpUAK7LIJaypT2MBiEHYtVk  
   YnKwwyYS8AdhUuBMsiLwVpC+VU7qB5+imZdn4w==  
   -----END CERTIFICATE-----
2. **Save certificate to a file**   
   Save the text between -{}BEGIN CERTIFICATE{}- and -{}END CERTIFICATE{}- (including this rows) to a new file with \*.cer extension

*** ** * ** ***

### **(2) Second way**

1. On a DC that is configured to support LDAPS, export a list of imported certificates:

   ***CertUtil -store -v MY***

   The output of this command is a list of certificates, separated by a row, as shown below "*==Certificate 0==*", where 0 is index of certificate.

   **Notes:**
   * You can redirect output of this command to a file (e.g., *CertUtil -store -v MY \> C:\\certificates.txt* ).   

   * You can use [Certificate Manager Tool](https://msdn.microsoft.com/en-us/library/bb727068.aspx) to export the certificate(s).
2. In the export list of certificates, find the certificate:

   * with subject that is DC FQDN (in our example below, it is "*DC.mulberry.com*")
   * in which one of certificate extensions is OID 1.3.6.1.5.5.7.3.1 (Server Authentication)
   * in which issuer is CA name (in our example below, it is "*ext*")
3. Get the certificate's index - this is a number, which appears in the separation header before each certificate (in the following fragment it is *== Certificate 0 ==*).

   ***Example*:**

   ```
   ================ Certificate 0 ================
   
   X509 Certificate:
   
   Version: 3
   
   Serial Number: 1b9b02cb00000000000c
   
   Signature Algorithm:
       Algorithm ObjectId: 1.2.840.113549.1.1.5 sha1RSA
       Algorithm Parameters: 05 00
   
   Issuer:
       CN=ext
   
    NotBefore: 19/07/2012 15:45
    NotAfter: 19/07/2013 15:55
   
   Subject:
       CN=DC.mulberry.com
   ..... 
   
   Certificate Extensions: 7
       2.5.29.15: Flags = 1(Critical), Length = 4
       Key Usage
           Digital Signature, Key Encipherment (a0)
       2.5.29.37: Flags = 0, Length = c
       Enhanced Key Usage
           Server Authentication (1.3.6.1.5.5.7.3.1)
    ......
   ```

**Save certificate to a file**

***CertUtil -store MY \<certificate_index\> \<path_to\>\\\<file_name\>***

*Example*:

`CertUtil -store MY 0 C:\ServerCert.cer`

*** ** * ** ***

-2- Import certificate to the keystore of Endpoint Security Server
------------------------------------------------------------------

1. Copy the certificate file to the Endpoint Security Server.
2. Go to the "*jre*" directory:

   * On Gaia OS: ***$UEPMDIR/engine/jre*** **Note:** On R80.x server -***$CPDIR/jre_32 and $CPDIR/jre_64***
3. Import the certificate to the both keystores (32 and 64):

   * On Gaia OS:

     **$CPDIR/jre_64/bin/keytool -import -keystore $CPDIR/jre_64/lib/security/cacerts -file \<file_path\> -alias \<alias\>
     $CPDIR/jre_32/bin/keytool -import -keystore $CPDIR/jre_32/lib/security/cacerts -file \<file_path\> -alias \<alias\>**

     ***Example*:**
     *$CPDIR/jre_64/bin/keytool -import -keystore $CPDIR/jre_64/lib/security/cacerts -file $UEPMDIR/cert.cer -alias SSLCert*   
     *$CPDIR/jre_32/bin/keytool -import -keystore $CPDIR/jre_32/lib/security/cacerts -file $UEPMDIR/cert.cer -alias SSLCert*

   You will be prompted to enter a password.  
   The default password is "**changeit**".

   At the end of the import, you will be asked "*Trust this certificate?\[no\]* " - confirm by entering ***y*** to complete the process.
   Output should be "*Certificate was added to the keystore* ".   

4. Restart the Endpoint Security Server:

   ***uepm_stop***
   ***uepm_start***

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
