<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>How-To: Issue Server Certificates in Keytos Shield on Keytos Docs</title>
    <link>https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/</link>
    <description>Recent content in How-To: Issue Server Certificates in Keytos Shield on Keytos Docs</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <copyright>ALL RIGHTS RESERVED. © 2026 Keytos</copyright>
    <lastBuildDate>Tue, 29 Sep 2026 09:00:00 -0400</lastBuildDate>
    <atom:link href="https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How-To: Create a RadSec Client Certificate in Keytos Shield</title>
      <link>https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/how-to-create-radsec-certificates/</link>
      <pubDate>Tue, 29 Sep 2026 09:00:00 -0400</pubDate>
      <guid>https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/how-to-create-radsec-certificates/</guid>
      <description>&lt;h2 data-toc-text=&#34;Overview&#34; id=&#34;overview---what-is-a-radsec-client-certificate&#34;&gt;Overview - What is a RadSec Client Certificate?&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#overview---what-is-a-radsec-client-certificate&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;When a network access point or switch connects to Keytos Shield via RadSec (RADIUS over TLS), it needs to present a client certificate that Keytos Shield can trust and validate. Some network devices, such as Cisco Meraki, use a certificate issued by the vendor&amp;rsquo;s own CA. However, for other network devices such as Unifi, you will need to install a RadSec client certificate that you created in Keytos Shield. This guide will go over creating a RadSec client certificate in Keytos Shield for RadSec authentication with your network controller.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How-To: Create a Domain Controller Certificate in Keytos Shield</title>
      <link>https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/how-to-create-domain-controller-certificates/</link>
      <pubDate>Tue, 29 Sep 2026 09:00:00 -0400</pubDate>
      <guid>https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/how-to-create-domain-controller-certificates/</guid>
      <description>&lt;h2 data-toc-text=&#34;Step-by-Step Guide&#34; id=&#34;step-by-step-guide---how-to-issue-domain-controller-certificates-in-keytos-shield&#34;&gt;Step-by-Step Guide - How to Issue Domain Controller Certificates in Keytos Shield&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#step-by-step-guide---how-to-issue-domain-controller-certificates-in-keytos-shield&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;Follow these steps to create and issue domain controller certificates in Keytos Shield.&lt;/p&gt;&#xA;&lt;h3 data-toc-text=&#34;Prerequisites&#34; id=&#34;prerequisites-for-creating-domain-controller-certificates-in-keytos-shield&#34;&gt;Prerequisites for Creating Domain Controller Certificates in Keytos Shield&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#prerequisites-for-creating-domain-controller-certificates-in-keytos-shield&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Before you begin creating domain controller certificates in Keytos Shield, ensure that you have completed all the necessary prerequisites:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.keytos.io/docs/keytos-shield/getting-started/&#34;&gt;The Keytos Entra ID applications are registered in your tenant&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.keytos.io/docs/keytos-shield/getting-started/&#34;&gt;You have signed up for a Keytos Shield Plan&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.keytos.io/docs/keytos-shield/manage-your-shield-subscription/&#34;&gt;You are a Subscription Owner or Network Administrator&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.keytos.io/docs/keytos-shield/secure-your-network/get-started-with-shield-network-security/&#34;&gt;You have completed the Keytos Shield Network Security onboarding&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Make sure you selected &lt;strong&gt;Hybrid infrastructure&lt;/strong&gt; for &lt;strong&gt;What type of environment do you have?&lt;/strong&gt; during onboarding.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-distribute-network-shield-network-profiles/distribute-shield-network-profiles-with-microsoft-intune/&#34;&gt;You have pushed your CA certificates to your Intune devices&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h3 data-toc-text=&#34;1 - Trust CA Certificates in Active Directory&#34; id=&#34;step-1---how-to-trust-your-keytos-shield-ca-certificates-in-active-directory&#34;&gt;Step 1 - How to Trust Your Keytos Shield CA Certificates in Active Directory&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#step-1---how-to-trust-your-keytos-shield-ca-certificates-in-active-directory&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;The first step is to add the Keytos Shield CA certificates to the NTAuth Store. This will enable the certificate to be used for authentication in Active Directory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How-To: Issue a Server Certificate in Keytos Shield</title>
      <link>https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/how-to-create-generic-server-certificates/</link>
      <pubDate>Tue, 29 Sep 2026 09:00:00 -0400</pubDate>
      <guid>https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-issue-server-certificates/how-to-create-generic-server-certificates/</guid>
      <description>&lt;div class=&#34;alert alert-info&#34; role=&#34;alert&#34;&gt;&lt;div class=&#34;h4 alert-heading&#34; role=&#34;heading&#34;&gt;Looking to issue client certificates to your users and devices?&lt;/div&gt;&#xA;&lt;p&gt;Check out our guides for &lt;a href=&#34;https://www.keytos.io/docs/keytos-shield/secure-your-network/how-to-distribute-network-shield-network-profiles/&#34;&gt;distributing client certificates&lt;/a&gt; via your Mobile Device Management (MDM) platform.&lt;/p&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 data-toc-text=&#34;Overview&#34; id=&#34;what-is-a-server-certificate-in-keytos-shield&#34;&gt;What Is a Server Certificate in Keytos Shield?&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#what-is-a-server-certificate-in-keytos-shield&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;p&gt;A server certificate is issued by Shield&amp;rsquo;s certificate authority (CA), with custom subject, names, lifetime and usages that you determine. This is most useful for anything that needs to trust Shield in your network: servers, appliances, domain controllers, or devices that don&amp;rsquo;t fit the built-in RadSec flow.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
