Hi Sven,
Did you figure out how to make this feagure works?
I'm facing the same issues like you. The feature is not working and I guess it's because even if you configure the certificate, the java application is using ldap instead of ldaps. This is like in vRO when you want to use the AD plugin and run the "Add user with password" workflow. Have the certs configured and use 636 is a requirement.
Regards,
Jose Gomez