denrepo

OracleSecurity & users

CMU step 2: export the AD root certificate

The database talks to AD over LDAPS, so its wallet must trust the certificate authority that issued the domain controllers' certificates. Export that root CA certificate in Base-64 and copy it to the database server. If an intermediate CA issued the DC certificates, export that one too.

19cRun on domain controller

Not yet verified. How scripts are tested

ora-cmu-root-cert.ps1
1# On a Windows machine that can reach the enterprise CA (often a DC), in PowerShell2# or a command prompt. If your PKI team runs the CA, ask them for the root CA3# certificate in Base-64 (.cer) instead.4 5# 1. Export the CA certificate (binary DER)6certutil -ca.cert C:\temp\ad_root_ca.cer7 8# 2. Convert it to Base-64 for orapki9certutil -encode C:\temp\ad_root_ca.cer C:\temp\ad_root_ca.txt10 11# 3. Check it's the right one: the Subject should be your root CA's name12certutil -dump C:\temp\ad_root_ca.txt13 14# 4. Copy ad_root_ca.txt to the database server, for example to /tmp (sftp or WinSCP).

Run these on a Windows domain controller.

Open in denrepo

Part of these runbooks

More Oracle scripts: Security & users