This is how I ended up accomplishing this (There may be simpler ways)
Make sure AD is set up authentication and communicating
Add authorities
CA with certificate only
CA intermediate with certificate and key
Add base and delta CRL
Log in with user who has permission to enroll
Create internal certificate:
Server
Sub CA
add oscp url
all the other goodies
Create and add to opnsense
A tad more to it than last time
Head hurts, off to get a beer.
Make sure AD is set up authentication and communicating
Add authorities
CA with certificate only
CA intermediate with certificate and key
Add base and delta CRL
Log in with user who has permission to enroll
Create internal certificate:
Server
Sub CA
add oscp url
all the other goodies
Create and add to opnsense
A tad more to it than last time
Head hurts, off to get a beer.