Windows Certificate Authority: Retrieve the CA (Root) Certificate

When setting up certificates in Universal ZTNA you must download the CA certificate also known as the root certificate from the certificate authority so that it can be uploaded into Universal ZTNA. Navigate to the domain controller certificate services site.

  1. Go to Microsoft Active Directory Certificate Services: https://<certificatedomain>/certsrv.
  2. Select Download a CA certificate, certificate chain, or CRL.
  3. Under Encoding method, select the Base 64 option and select Download CA certificate.
  4. If web-based certificate services are not enabled, you can open the Certification Authority window from Server Manager on the Active Directory machine, right-click on the CA and select Properties.
  5. Under the General tab, select View Certificate.
  6. Under the Details tab, select Copy to File.
    The system displays the Certificates Export Wizard.
  7. In the Export File Format section, select the Base-64 encoded X.509 option and select Next.
  8. In the File to Export section, under File name, select Browse.
  9. Navigate to a directory where the file will be saved, enter an appropriate name, and select Save.
  10. To complete the process, select Next.
    The file will be downloaded with a .cer extension.
    Note

    Note

    Before the file can be uploaded you must rename the file with a .pem extension.

To upload the certificate to Universal ZTNA, go to Manage CA Trusted Root Certificates in Universal ZTNA.