The following installation tasks must be completed in the order that they are listed. If a step is not necessary for your setup, you can skip it.
If you want to set up your own CA in order to configure SSL on AD LDS/ADAM, you need to install Internet Information Services (IIS).
On your Windows Server computer, access the Control Panel, then click
.In the left pane, select
.Select
, then click .Select
, then click .Verify that at least the following are selected:
Click
twice, then click to complete the installation.You might be prompted to insert your original installation media for Windows Server.
On your Windows Server machine, access the Control Panel, then click
.In the left pane, select
.Select to
, then click to complete the installation.If you are installing AD LDS, use the steps given at the Microsoft TechNet Web site, then follow the installation instructions from Step 6 to Step 16 from the Installing ADAM
section.
On your Windows Server machine, access the Control Panel, then click
.In the left pane, select
.Select
, then click .Select
, then click .Click
to complete the installation.Click
.Select
to create an application directory partition, unless you plan on doing it later.Specify the DN of the location where you'd like to synchronize users. For example, CN=People,DC=adamtest1,DC=COM.
Click
.NOTE:If you specify a port number for the ADAM instance other than the default, ensure that you configure the Identity Manager ADAM driver to use the non-default port, as well. For more information about configuring the ADAM driver, see Creating the AD LDS/ADAM Driver in iManager.
Leave the default locations for data files and data recovery files, then click
.Select an account for the ADAM service, then click
.If you are installing ADAM on a server that is not already part of a domain, you might get a warning at this point. This is usually not a problem with ADAM, and you should continue with the installation.
Click
to assign the current user (the one you are logged in as) rights to administrate ADAM.Select
.Select
, then click .Click
.Review the installation summary, then click
.On the server where you installed IIS and Certificate Services, specify the following address in a Web browser: http://localhost/certsrv.
You should see a welcome message from Certificate Services. If you do not, go back and make sure you have IIS and Certificate Services both installed.
The steps for requesting and installing a certificate are found at [.NET] Using SSL with ADAM (AD LDS)
.
On your AD LDS/ADAM server, make sure you have the certificate installed in the following location in MMC: Certificates - Service (adaminstance) on Local Computer\ADAM_adaminstance\Personal directory.
On the Identity Manager server (or the Remote Loader computer) where the driver is running, make sure that you have only the CA certificate and make sure it is in Certificates - Current User\Trusted Root Certificates directory.
See Active Directory Application Mode Technical Reference
for additional resources.