Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-9620: How to deploy the IWA Root CA to workstations using Group Policy

App Access Service ,   Mac & PC Management Service ,  

27 December,17 at 09:18 PM

Question:


How can you deploy the IWA Trusted Root CA to multiple workstations using Group Policy?







Resolution:

1. Download the IWA Root CA from the Admin Portal > Settings > Network > Centrify Connectors


User-added image




2. Modify your Connector


User-added image




3. Go to "IWA Service" and click on "Download your IWA root CA certificate"



User-added image



To deploy the trusted connector root CA certificate to a group policy object:

1. Open the group policy object (GPO) that you want to edit.

2. In the Group Policy Management Editor, navigate to the following policy location:

PolicyObjectName/Computer Configuration/Windows Settings/ Security Settings/public Key Policies/Trusted Root Certification Authorities.

User-added image


3. On the Action menu, point to All Tasks, and then click Import.
User-added image

4. The Certificate Import Wizard opens. The wizard guides you through the process of importing the root certificate and installing it as a trusted root certification authority (CA) for this GPO.



User-added image

User-added image

User-added image

User-added image

User-added image


5. The certificate will display as such

User-added image


6. The certificate will apply based on the Group Policy update interval. 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.