I have configured Jira for ldap over 636, and imported our ca certs into the keystore. While everything appears to work from Jira's side of things, from the AD side we are seeing this error:
Schannel 36887 - A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 46
More on this error code:
https://blogs.msdn.microsoft.com/kaushal/2012/10/05/ssltls-alert-protocol-the-alert-codes/
This seems to work fine with confluence (same certs). I cannot, for the life of me, figure out what to do with this one. I have re-imported certs (multiple ways), converted from JKS to PKCS12 (and back again), and everything else I can think of.
I could sure use some pointers.
Encrypted LAN trace shows Jira request some info, AD hands it back with a cert, and we reject it as unknown or mangled. Connection is then reset. Again, everything appears to be working fine symptomatically, but it is bugging our AD admin to no end.