When the "Refresh LDAP group" is selected PAM displays an error message "Unable to connect to domain DC=Forwardinc,DC=COM. All configured LDAP servers are down. Connection to LDAP Server ldaps.forwardinc.com Port 636 failed. Failing over to the next configured server for the domain."
After trying several times to refresh, the LDAP group is refreshed.
The AD/LDAP servers are available and all are up. There are hosted in WIndows 2016.
The LDAP logs show the following error everytime that the LDAP Refresh group fails:
<message>Exception failed trying to acquire ldap context to Server ldaps.emea.dsv.com Port 636</message>
<message>javax.naming.CommunicationException: ldaps.emea.dsv.com:636 [Root exception is javax.net.ssl.SSLException: java.lang.RuntimeException: Could not generate DH keypair]