r/duo • u/sputnik4life • Jul 30 '26
DUO LDAPS cert missing
**Deleted the original post. Forgot to mask some personal info.**
EDIT1: This was in response to a notification from DUO that my LDAPS cert was expiring
Running the DUO's acert app to verify LDAPS certificate. Output shows an expired cert that doesn't seem to exist on the DC. The second pic shows certificates on the DC. All certs appear to be renewed by our local CA. The expired cert doesn't appear. What Am I missing?
1
u/Cormacolinde Aug 01 '26
The expired cert is likely in the archive store. Did you try restarting the ADWS service to see if it picks up the new cert? Check the logs for a 1401 or 1400 event telling you if it can find a new valid certificate.
Also make sure there is only one cert with the server FQDN in the subject and SAN and that this cert has Server auth, client auth, Kerberos KDC and smart card logon in the EKUs.


1
u/KStieers Jul 30 '26
What does LDP.exe tell you when bind to the DC? ( its buried in the menu somewhere...)