Active Directory Certificate Services automation
The CA connector is a small Windows service on your AD CS server. It lets every aethercert agent request certificates from your Enterprise CA through your own templates - and reports on the health of the CA while it is there.
At a glance
- Connector
- Windows service on the AD CS server; installed and updated like the agent
- Listener
- :8443 on your internal network; only agents connect to it
- Authorization
- Single-use ES256 token per job, verified locally and live with aethercert
- Rights needed
- Enroll on the template; Issue and Manage Certificates on the CA (for revocation)
- Health checks
- CRL and delta CRL freshness, CDP reachability, CA certificate expiry, weak keys, ESC6
What it does
Agents send their signing requests to the connector on your internal network. The connector submits them to AD CS with certreq against the template you configured and returns the issued certificate. Every request must carry a short-lived, single-use token minted by aethercert for that specific job, and the requested names are checked against it before anything reaches the CA.
On each check-in the connector also reports the CA's state: base and delta CRL freshness, reachability of every CDP location, CA certificate expiry, weak CA keys or signature algorithms, and whether EDITF_ATTRIBUTESUBJECTALTNAME2 (ESC6) is enabled. Findings appear in the dashboard and the event log; a hardening checklist covers what cannot be checked remotely.
How it runs
- 01
Install and pair
Run the installer on the CA server with a one-time pairing token. It finds the Enterprise CA in Active Directory and listens on :8443.
- 02
Grant rights
Give the connector's account Enroll on the template and Issue and Manage Certificates on the CA. A read-only preflight checks every prerequisite.
- 03
Request
An agent sends its CSR with a job-bound token; the connector verifies it locally and with aethercert, then submits to AD CS.
- 04
Report
Check-ins report templates and CA health; findings raise events and alerts.
What you configure
- Certificate template (default WebServer)
- Listen address (default :8443) and optional own TLS certificate
- Service account: LocalSystem, a dedicated account or a gMSA
Prerequisites
- An Enterprise CA in Active Directory
- Windows Server for the connector, normally the CA server itself
- Agents able to reach the connector on the internal network
Limitations
- AD CS requires the Standard plan or higher.
- The connector reports CA health but never changes the CA, templates or ACLs - remediation stays with you.
Related features
Solutions
More in Certificate authorities
Documentation
Frequently asked questions
Active Directory Certificate Services (AD CS)
Does the connector need inbound access from the internet?
No. Agents on your network connect to it; it connects out to aethercert for check-ins and token verification.
Can aethercert change my CA configuration?
No. The connector only submits and revokes requests and reads CA state. Hardening findings tell you what to change; you change it.
Automate Active Directory Certificate Services (AD CS)
Connect it once in the dashboard; every issuance and renewal uses it from then on.
Community plan, no card required. Open registration - your account is ready in a few minutes.