Currently we have LDAPS configured on our AD controller with a certificate from an external PKI. I have followed the instructions on how to add the certificate(s) to the keystore but I still get an error.
I've added the Root and the Intermediate to the cacerts file with their own alias's and then imported the server cert from the ad controller. The error I get seems to suggest that the chain is not able to be followed:
Connection test failed. Response from the server:
adserver.fqdn.local:636; nested exception is javax.naming.CommunicationException: adserver.fqdn.local:636 [Root exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target]
I've tried a few other things but I can't seem to figure out how to link the certs together. it seems like it should use the thumbprint from each cert to follow the chain of trust but doesn't seem to be working...