Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Install the LDAP X.509 SSL certificate

You can install an X.509 certificate for your LDAP integration.

Before you begin

Role required: admin

Procedure

  1. Purchase or generate an SSL certificate on your LDAP server.

  2. Navigate to LDAP > Certificate and click New.

  3. Fill in the form fields:

    FieldDescription
    NameThe certificate name.
    Expiration notificationSelect this option to send a notification to the users selected in the Notify on expiration field. By default, this is enabled.
    Notify on expirationSelect the users to revive the notification regarding certificate expiration. If no users are selected, the logged in user is added by default, along with the last two logged in users with the administrator role.
    Warn in days to expireThe number of days before expiration that the instance send the notification. Enter a value of at least 20. Instances upgraded to Istanbul and later releases have this value set to 20 unless a greater value is specified.
    ActiveA check box to indicate that this certificate is active.
    FormatThe format of the certificate.
    TypeThe certificate container. The instance recognizes certificates from trust stores, Java keystore, and PKCS#12 keystores.
    Valid fromThe instance automatically adds the certificate valid from date to this field. Attach the certificate to the X.509 certificate record to populate this field.
    ExpiresThe instance automatically adds the certificate expiration date to this field. Attach the certificate to the X.509 certificate record to populate this field.
    Expires in daysThe calculated number of days to expiration.
    Short descriptionA description for the certificate.
    IssuerThe instance automatically adds the certificate issuer to this field. Attach the certificate to the X.509 certificate record to populate this field.
    SubjectThe instance automatically adds the certificate subject to this field. Attach the certificate to the X.509 certificate record to populate this field.
    PEM CertificateEnter the value of the X509 certificate.

    Note: The integration does not currently sign the certificate in communications between the instance and the IdP.

  4. Click Save.

What to do next

Click Validate Stores/Certificates to test the trust store and certificate.