Upcoming Active Directory Certificate Changes and Required Review of LDAP Dependencies

The Active Directory SSL certificate will no longer contain names ending in 'ad.uillinois.edu'. Service owners will need to update to use load-balanced addresses (ldap.illinois.edu or ldap-ad-aws.ldap.illinois.edu).

Effective February 2027, the Identity & Access Management team will be making changes to the Active Directory LDAP certificate. These changes are being driven by updates to certificate issuance requirements and may affect applications or services that rely on specific Subject Alternative Names (SANs) currently present in our LDAP certificates.

What's Changing?

Today, the Active Directory LDAP certificate contains SAN entries for:

  • ad.uillinois.edu
  • UDC01.ad.uillinois.edu
  • UDC02.ad.uillinois.edu
  • All other individual *.ad.uillinois.edu domain controller FQDNs
  • ldap.ad.uillinois.edu
  • ldaps.ad.uillinois.edu
  • ldap.illinois.edu
  • ldap-ad-aws.ldap.illinois.edu

Following this change, certificates will no longer include any *ad.uillinois.edu names. Certificates will only contain these LDAP service names in the illinois.edu namespace:

  • ldap.illinois.edu
  • ldap-ad-aws.ldap.illinois.edu

This change is required because the ad.uillinois.edu DNS zone is not publicly resolvable and no longer meets certificate provider validation requirements.

What Is Not Affected?

This change does not affect domain-joined Windows computers or systems that use the kerberos.illinois.edu service for authentication. Kerberos authentication and standard domain operations will continue to function normally and are not dependent on the LDAP certificate Subject Alternative Names (SANs) that are being removed as part of this change.

The impact is limited to applications, services, appliances, and scripts that directly connect to LDAP or LDAPS and perform certificate validation against names that will no longer be present in Active Directory LDAP certificates.

Action Required

Service owners and administrators should review any systems, applications, scripts, appliances, or integrations that:

  • Connect to LDAP or LDAPS services
  • Perform certificate validation against LDAP servers
  • Reference hostnames ending in ad.uillinois.edu
  • Pin or explicitly trust LDAP certificates based on SAN entries

If your service connects to any hostname ending in ad.uillinois.edu, or validates certificates against those names, update your configuration before February 2027. Services that continue to rely on *.ad.uillinois.edu certificate names may experience certificate validation failures after this change is implemented.

Supported LDAP Endpoints Going Forward

For load-balanced LDAP access, there will be two supported service addresses:

Supported LDAP addresses

Resources in AWS

ldap-ad-aws.ldap.illinois.edu

All other resources

ldap.illinois.edu

These are the only supported load-balanced LDAP addresses that services should use moving forward. See [Link for document 78999 is unavailable at this time] for more information.

Applications and services should not rely on:

  • Individual domain controller names (*.ad.uillinois.edu)
  • ldap.ad.uillinois.edu
  • ldaps.ad.uillinois.edu
  • ad.uillinois.edu

Service admins and departmental IT Pros should review existing configurations and update them to one of the two supported endpoints listed above.

Consider Modern Authentication

If your application currently uses LDAP for authentication, this is a good opportunity to evaluate migration paths to more modern authentication protocols such as SAML or OIDC where possible.

Benefits of modern authentication include:

  • Reduced dependency on Active Directory LDAP infrastructure
  • Better support for Multi-Factor Authentication (MFA)
  • Improved security controls and Conditional Access capabilities
  • Support for passkeys and passwordless authentication
  • Simplified future infrastructure and certificate changes
  • Alignment with Microsoft's strategic identity platform direction

While LDAP will continue to be available for supported use cases, organizations planning application upgrades or authentication modernization efforts are strongly encouraged to evaluate modern authentication options.

Additional Benefits of This Change

This update also helps prepare University services for upcoming industry-wide reductions in certificate validity periods. Certificate authorities and browser vendors continue to move toward shorter certificate lifetimes requiring organizations to renew and replace certificates more frequently.

By standardizing on a small number of supported LDAP service names, we can simplify future certificate management and make the transition to automated certificate renewal processes significantly easier. This reduces administrative overhead, minimizes the risk of service disruptions during certificate replacement events, and improves the long-term sustainability of our identity infrastructure.

If you have questions about how this change may impact your service, please contact adsupport@illinois.edu.



Keywords:
ActiveDirectory Active Directory LDAP Certificate 
Doc ID:
163623
Owned by:
Active Directory G. in University of Illinois Technology Services
Created:
2026-08-26
Updated:
2026-09-24
Sites:
University of Illinois Technology Services