Hi All,
For secure AD authentication it seems Sophos advice is to install AD CS and create an AD CA on every AD server you use.
Sophos support confirmed this is the way to go. For me this seems like overkill. IBM even states on there website not to do this; "Do not install the Certificate Services role on the Active Directory server. Some Active Directory Domain configurations are not suited to accept an installed Certificate Services role. For example, when there are multiple Active Directory servers in a domain." Link: https://www.ibm.com/docs/en/tsm/7.1.1?topic=passwords-configuring-windows-active-directory-tlsssl
Just to check with the community, why not use a public CA certificate? Then there is no need to install AD CS on every AD.
Did anybody already tried this? And please share your thoughts on this.
This thread was automatically locked due to age.