Certificate Types & Requirements for Laserfiche Directory Server

To facilitate user authentication and secure communication between Laserfiche Directory Server and other clients, it is recommended for all certificates to meet the following requirements:

Additional Requirements:

  1. The certificate bound to port 443 in Internet Information Services (IIS): This is the HTTPS TLS certificate that is used by the browser to secure communication between the browser and IIS.
  2. The certificate bound to port 5049 in XMLEndpointUtility: This certificate is used to secure communication between Laserfiche Directory Server and Laserfiche applications using HTTPS (including STS).
  3. The server certificate used for alternate service on the Laserfiche Directory Server Machine: This certificate is used to secure Windows Communication Foundation (WCF) communication between end applications and Laserfiche Directory Server when using alternate service (certificate authentication).
  4. The client certificates used for alternate service on the application machines: These certificates are used to secure Windows Communication Foundation (WCF) communication between end applications and Laserfiche Directory Server when using alternate service (certificate authentication).
  5. The certificate used by the Laserfiche SCIM Service for communication with Laserfiche Directory Server: This certificate is used to secure communication between the Laserfiche SCIM Service and Laserfiche Directory Server.
    • Key Usage includes the Client Authentication extension.
    • The SCIM Service must have the private key to its certificate.

Note: To learn more about Directory Server and Security Token Service (STS) configuration, navigate to the Initial Configuration page.

Note: To learn more about single sign on, navigate to Configuring Single Sign-On for Laserfiche Web Products.