Copying the Active Directory certificate to the UCS system

Hello,

In this documentation :
https://docs.software-univention.de/manual/latest/en/windows/ad-connection.html#copying-the-active-directory-certificate-to-the-ucs-system
It is written : This is done by clicking on Upload in the sub menu Active Directory connection SSL configuration.
I’ve searched and searched, but I can’t find this sub-menu or this ‘Upload’ button.
A kind soul to enlighten me?

P.S. : I’m retired and I help IT people install Open Source solutions.

On the server where the “Active Directory Connection” is installed select In UMC the (turquoise) Domain modules.

If you open the Module you should see this:

hth,
Dirk

Thank you. However, I think this option only appears after a successful first setup. In my case, I am still at the first wizard stage, with the following screen :

I would like to choose the second option (Synchronisation of account data between an Active Directory and this UCS domain).
Then I get the Security settings error :

As requested, I created a certification authority on the Active Directory server.
After that, I would have to import it, as indicated in the aforementioned documentation.
But the Active Directory Connection module doesn’t have an Upload button yet at this point…
How and where to put this certificate ?

Thanks in advance,
Daniel

It looks like you need to continue with the wizard. The ability to upload the certificate for the first time will be shown in one of the next steps.
The documentation 9.2.3.1. Basic configuration of the UCS AD Connector has some remarks.
Additional note from my side: The last time I had to configure an AD conncetion the static hosts entry did not work for me. Instead, I configured conditional forwarding as described in 9.4. Trust relationships (without trust relationship itself)

Best Regards
Dirk

Thanks for the encouragement :wink:

After clicking on next :

and then :

I chose bidirectional and then :

I didn’t have the ability to upload the certificate. I don’t know if I should worry about it.

Best Regards,
Daniel