I've configured Confluence 5.2.5 for an External Microsoft AD User Directory, using SSL.
On completing the config screen and clicking 'quick test' I get the 'PKIX path building failed' exception, which is identical to the one seen when there is no certificate in the keystore matching the server connected to.
However, if I run confluence with the java ssl debug flag (' -Djavax.net.debug=ssl ') then the same test succeeds, and I am able to fully sync the directory. Restarting Confluence with the debug flag removed allows synchronisation to continue to work.