Active Directory does not contain a shared certificate store. When configuring Active Directory-based IPsec policy to use ...

Active Directory does not contain a shared certificate store. When configuring Active Directory-based IPsec policy to use certificate authentication, you must ensure that each domain member has an appropriate certificate installed.

Do you want to select a certification authority from the certificate store on the local computer?