Active Directory Certificate Authority
By default, the Password Reset Portal will send all Active Directory tasks to your core Passwordstate webserver. Your Passwordstate web server will then attempt to communicate to your domain using the Kerberos protocol by default.
If you do not wish to use Kerberos, you can instead use LDAPS, or LDAP over SSL. When using LDAPS, you must have installed/configured a Certificate Authority in each of the domains where you wish to reset or unlock user’s domain accounts. This will honour any Domain Password Policies, or Fine-Grained Password Policies from these domains.
Please follow these step-by-step instructions to set up a Certificate Authority:How to Set Up a Internal Certificate Authority