Quick troubleshooting view
LDAP clients no longer trust the certificate or the domain controller presents an unexpected certificate.
- SAN does not contain the FQDN in use
- Missing intermediate chain
- Old certificate still selected
- Test port 636 and inspect the certificate
- Compare the hostname used by the client
- Check the local computer certificate store
- Correct only the component confirmed by the checks
- Retest the original symptom after the change
- Escalate with collected evidence when the cause remains unclear
Contextual technician plan
Perform this check and preserve the observed result before changing configuration.
“Test port 636 and inspect the certificate” should produce an observation that clearly confirms or rules out “SAN does not contain the FQDN in use”.
If the observation is normal, lower “SAN does not contain the FQDN in use” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “SAN does not contain the FQDN in use” first. Related action: Correct only the component confirmed by the checks.
Perform this check and preserve the observed result before changing configuration.
The exact failing name should resolve through the expected DNS server to the expected record without timeout.
If the exact name resolves correctly, compare application cache, suffix/search domain and the client or network where the failure remains.
If resolution fails or returns the wrong record, keep the queried server and answer and correct the resolver, zone/record or DNS path that is actually wrong.
Perform this check and preserve the observed result before changing configuration.
“Check the local computer certificate store” should produce an observation that clearly confirms or rules out “Old certificate still selected”.
If the observation is normal, lower “Old certificate still selected” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Old certificate still selected” first. Related action: Escalate with collected evidence when the cause remains unclear.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Escalate with the exact symptom, scope, timestamp and completed checks when the issue remains unresolved.
+Open the complete detailed guideDetailed explanations and original troubleshooting content.
LDAP clients no longer trust the certificate or the domain controller presents an unexpected certificate.
Likely causes
- SAN does not contain the FQDN in use
- Missing intermediate chain
- Old certificate still selected
- Incorrect EKU
Checks in priority order
- Test port 636 and inspect the certificate
- Compare the hostname used by the client
- Check the local computer certificate store
- Verify trust and revocation
When to escalate
Escalate when the failure affects multiple users, a production dependency is unavailable, or logs show a component outside your control. Include timestamps, scope, tests already performed, and the last known working state.