hostname configured for ldap server does not match the hostname in servers certificate subject or SAN
Below is the screenshot of the error:

VMware NSX
The LDAPS servers were originally added to the configuration using IP addresses. The certificate presented to NSX does not have the LDAPS server IP addresses listed as a Subject Alternative Name (SAN) and because the IP address does not match the expected hostname in the certificate, the connection is rejected.
To resolve this issue, reconfigure the LDAPS servers using their Fully Qualified Domain Name (FQDN):
Log in to the NSX UI.
Navigate to User Management > Identity Providers.
Remove the existing LDAPS servers that are currently configured with IP addresses.
Re-add the LDAPS servers using their exact FQDN instead of IP addresses.
Save the configuration and verify that the connection status now shows as successful.
If the issue persists even after following the above steps, please open a case with Broadcom support team.