adselfservice-plus-ssl-installation-guide_2
adselfservice-plus-ssl-installation-guide_2
https
www.adselfserviceplus.com
Table of contents
Document summary 1
Step 3� Submit the generated CSR file to your certificate authority (CA) 4
www.adselfserviceplus.com
Document summary
This document guides you through the process of securing the connection between the ADSelfService
Plus’ server and the users’ browser using Secure Sockets Layer (SSL) certificates.
These features, designed to strike a balance between ensuring network security and ease-of-access,
warrants improved ROI and a more productive IT workforce.
1
www.adselfserviceplus.com
Configuration steps
Step 1� Enable HTTPS in ADSelfService Plus
If the default port number cannot be used, enter a designated HTTPS port number.
Click Save.
2
www.adselfserviceplus.com
Choose Generate Certificate and fill in all the necessary fields as given in the below table:
Common Name The name of the server in which ADSelfService Plus is running
Organizational Unit The department name that you want to appear in the certificate
Country Code The two-letter code of the country in which your organization is located
Password A password must be at least six characters; the more complex the
password, the better the security
Validity (In days) The number of days the certificate should be valid; if no value is
provided, it will be set to 90 days
Public Key Length The public key length; the larger the size, the stronger the key.
(In bits) The default size is 1024 bits and can be incremented only in multiples of 64
3
www.adselfserviceplus.com
Once you’ve entered all the details, click Generate CSR.
If you wish to apply for a self-signed certificate, click Generate & Apply Self-Signed Certificate.
Then follow the next steps.
Step 3� Submit the generated CSR file to your certificate authority (CA)
You can locate the SelfService.csr file in the certificates folder under <Install_Directory>\webapps\
adssp\ (Default location: C:\Program Files\ManageEngine\ADSelfService Plus\webapps\adssp\).
There are two ways to bind the CA-signed certificates with ADSelfService Plus. One way is through the
Apply Certificate section in the ADSelfService Plus admin portal, and the other method is manual
configuration. Any of the two methods can be used depending on preference. Below are the steps for
each method:
1. In the ADSelfService Plus admin portal, go back to Admin > Product Settings > Connection.
5. In the Certificate Password field, enter the password of the uploaded certificate.
6. Click Apply.
4
www.adselfserviceplus.com
Option 2� Manual configuration
Prerequisite: If the certificate bundle you received from your CA is not in the PFX format,
make sure you convert the certificate file along with the private key to a PFX file.
1. Back up the server.keystore, SelfService.p12, server.xml, and web.xml files located at <Install_Directory
>\conf (Default location: C:\ManageEngine\ADSelfService Plus\conf).
3. Open the server.xml file, located in the <Install_Directory>\conf folder, in a text editor.
Scroll down to the end of the file where you’ll find a connector tag as shown below:
<Connector SSLEnabled="true" ……
/>
5. Restart ADSelfService Plus, and check if the certificates are installed correctly.
When installing SSL certificates to protect MFA for machines, VPNs, OWA, and cloud applications—and
while installing the login agent on client machines—it is mandatory for the ADSelfService Plus Access
URL's protocol to be set to HTTPS.
5
www.adselfserviceplus.com
To do this:
Go to Admin > Customize > Product Settings > Connection > Connection Settings >
Configure Access URL.
Click Save.
Note: If your deployment of ADSelfService Plus uses an internet-facing endpoint such as a proxy server,
the Access URL must point to the proxy server.
If you have configured FIDO passkey authentication, setting the Access URL to HTTPS will modify
the preconfigured FIDO RP ID, resulting in loss of enrollment data and disenrollment of all users.
If you are planning on configuring FIDO passkey authentication, ensure that the Access URL is set to
HTTPS before configuring FIDO passkey authentication to prevent loss of enrollment data.
Our Products
AD360 | Log360 | ADManager Plus | ADAudit Plus | RecoveryManager Plus | M365 Manager Plus
ADSelfService Plus is an identity security solution to ensure secure and seamless access to enterprise
resources and establish a Zero Trust environment. With capabilities such as adaptive multi-factor
authentication, single sign-on, self-service password management, a password policy enhancer, remote
work enablement and workforce self-service, ADSelfService Plus provides your employees with secure,
simple access to the resources they need. ADSelfService Plus helps keep identity-based threats out,
fast-tracks application onboarding, improves password security, reduces help desk tickets and
empowers remote workforces.
For more information about ADSelfService Plus, visit
www.manageengine.com/products/self-service-password.