A hosted service wants to authenticate against our AD. They recommend using LDAPS. What is best practice? Install a public certificate on a DC. For instance on DC1.contoso.com. Then would I open up 443 on the firewall to that DC and allow from that IP? How would that affect other local LAN clients authenticating to that DC?