NOTE: The TLS certificate used for LDAPS must be created using Active Directory Certificate Services!
Export Root CA from Active Directory Server
Log into the Active Directory domain server as domain administrator:
Click Start 🢂 → Windows Administrative Tools 🢂 → Certificate Authority to open the CA Microsoft Management Console (MMC) GUI.
Highlight the CA server and right-click to select CA Properties:
From General menu, click View Certificate:
Select the Details view and click Copy to File on the lower-right corner of the window:
Use the Certificate Export Wizard to save the CA certificate file:
Click Next, then select Base-64 encoded X.509 (.CER):
Click Browse to select path to save the root-CA:
Click Finish.
...