Jeff Gamsby wrote: >Thanks. Yes, I understand that. > >From what I understand, the FDS (client, certutil db) is trying to talk to >the AD (server, Microsoft CA) and the PassSync cert db just has the >trusted FDS server certs (for synchronization). > >Do I need to import the FDS server certs into AD, or export the AD certs >into the FDS server? > > The FDS cert database needs to contain an exported copy of the CA cert used to sign the AD's server cert.