Directory syncs fail and users are unable to log in to VMware Identity Manager (vIDM) using directory accounts. Attempts to log in results in the error message: "Error Call to Directory Service failed."
VMware Identity Manager 3.3.7
The issue is caused by an invalid or incomplete SSL certificate chain on the AD server. Logs indicate a javax.net.ssl.SSLHandshakeException due to a java.security.SignatureException: certificate does not verify with supplied key. This typically occurs when root or intermediate certificates are incorrectly installed, leading to a chain where issuers are not properly aligned.
To resolve this issue, ensure a valid and complete certificate chain is installed on the AD servers: