Entra Domain Services and Secure LDAP - Feature Requests - Let's Encrypt Community Support
I've read several articles and I've built out an automation using PoSH-ACME that works for normal SSL services. However, there are some limitations that are causing issues with LDAP/Domain Controller/Domain Services. Secure LDAP in Entra Domain Services requires a wildcard certificate. Domain controllers require the FQDN of the server in either the subject or SAN. A wildcard cert from LetsEncrypt can't include the FQDN of any domain controller because LetsEncrypt considers this "redundant." ...