>> Additionally, for applications or appliances, should the Root CA certificate or the Intermediate CA certificate be used?
In general, the root CA only issues certs for the intermediate CA. Nothing else. (Not strictly true – but it shouldn’t be issuing application level or end-user visible certs.)
To answer the question in the subject line, the answer is “both”.
>> My question is: Which certificate should be used on the application side in this scenario?
I’m not sure I understand this question. The application will connect to the DC and validate that certificate. It doesn’t need its own certificate.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion visit
https://groups.google.com/d/msgid/ntsysadmin/c0b27d5a-a636-47a1-96ad-154735f1f3afn%40googlegroups.com.
On Dec 11, 2025, at 3:11 PM, Michael B. Smith <mic...@smithcons.com> wrote:
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/a193a936aaa34333bdb1214eb8b8adf9%40smithcons.com.
Excellent point! Mutual authentication.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/98741E00-8928-41A8-88F7-5583045FF6C4%40gmail.com.