{"id":36,"date":"2012-07-26T11:11:00","date_gmt":"2012-07-26T09:11:00","guid":{"rendered":"https:\/\/test.n3oxid.fr\/?p=36"},"modified":"2021-04-18T21:13:29","modified_gmt":"2021-04-18T19:13:29","slug":"activation-du-ldaps-pour-le-service-active-directory-sous-windows-2003","status":"publish","type":"post","link":"https:\/\/www.n3oxid.fr\/?p=36","title":{"rendered":"Activation du LDAPS pour le service Active Directory sous Windows 2003"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Installation de IIS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e9marrer &gt; Ex\u00e9cuter &gt; appwiz.cpl &gt; Ajouter ou supprimer des composants Windows<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Composant Windows&nbsp;: Serveur d&#8217;applications &gt; Services IIS &gt; Service World Wide Web<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Installation de l&#8217;autorit\u00e9 de certification<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e9marrer &gt; Ex\u00e9cuter &gt; appwiz.cpl &gt; Ajouter ou supprimer des composants Windows<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Composant Windows&nbsp;: Service de certificats &gt; Autorit\u00e9 de certification de services de certificats<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Type de certificat : Autorit\u00e9 racine d'entreprise\nCN : HomeCA\nDN : DC=home,DC=local\nP\u00e9riode de validit\u00e9 : 5 ans\nDB certificats : C:\\WINDOWS\\system32\\CertLog\nDB journal DB certificats : C:\\WINDOWS\\system32\\CertLog\n<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Forcer la cr\u00e9ation d&#8217;un certificat serveur<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e9marrer &gt; Ex\u00e9cuter &gt; mmc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ajouter le composant Certificats pour le compte de l&#8217;odinateur (local)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Se placer sur la magasin Personnel puis emettre une requp\u00eate de certificat via le menu contextuel :<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Toutes les t\u00e2ches &gt; Demander un nouveau certificat<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Type de certificat : Contr\u00f4leur de domaine\nNom convivial : vm-dc1.home.local\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><ins>Remarque<\/ins>&nbsp;: cette manipulation est \u00e0 faire sur l&#8217;ensemble des contr\u00f4leurs de domaine<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Test d&#8217;acc\u00e8s LDAPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e9marrer &gt; Ex\u00e9cuter &gt; ldp<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Connection &gt; Connect<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Server : vm-dc1.home.local\nPort: 636\nSSL : actif\n<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Autoriser les requ\u00eates de certificats pour tous les contr\u00f4leurs des domaines enfants<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ouvrir la console de gestion de l&#8217;Autorit\u00e9 de Certification :<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Outils d&#8217;administration &gt; Autorit\u00e9 de certification<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Modifier les autorisations de l&#8217;AC :<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">clic droit sur HomeCA &gt; Propri\u00e9t\u00e9s &gt; Onglet S\u00e9curit\u00e9,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ajouter le groupe Contr\u00f4leurs de domaine de chaque domaine et les autoriser \u00e0 demander des certificats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ajouter le groupe Contr\u00f4leurs de domaine de chaque domaine dans le groupe CERTSVC_DCOM_ACCESS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mettre \u00e0 jour les param\u00e8tres de s\u00e9curit\u00e9 DCOM pour les services de certification&nbsp;:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">certutil -setreg SetupStatus -SETUP_DCOM_SECURITY_UPDATED_FLAG<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Red\u00e9marrer le service Distributed Transaction Coordinator&nbsp;:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">net stop msdtc\nnet start msdtc\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Red\u00e9marrer l&#8217;Autorit\u00e9 de certification&nbsp;:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">net stop certsvc\nnet start certsvc<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Installation de IIS D\u00e9marrer &gt; Ex\u00e9cuter &gt; appwiz.cpl &gt; Ajouter ou supprimer des composants Windows Composant Windows&nbsp;: Serveur d&#8217;applications &gt; Services IIS &gt; Service World Wide Web Installation de l&#8217;autorit\u00e9 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[20,21,22,23],"class_list":["post-36","post","type-post","status-publish","format-standard","hentry","category-computing","tag-ldaps","tag-microsoft","tag-pki","tag-windows"],"_links":{"self":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts\/36","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=36"}],"version-history":[{"count":1,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts\/36\/revisions"}],"predecessor-version":[{"id":37,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts\/36\/revisions\/37"}],"wp:attachment":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=36"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=36"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=36"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}