You won't have TLS settings until you have the firmware updated, same for the Network trace feature
We don't have the TLS settings? Would they be somewhere else? We also don't have the Network Troubleshooting Logs option.
We validated NTP and that isn't an issue.
Update the firmware on one that does work and one that doesn't (see attached)
Enable network trace and try the ldap, then compare failed and successful in wireshark
CWIS > Properties > Security > Logs > Network troubleshooting
Things that will casue LDAPs to fail:
Time off by more than 3 minutes
Not having HTTPs enabled on the MFP
TLS Settings
I have 5 Xerox Workcentre 5955's located in 4 offices around the state. In one of those offices, I also have an AltaLink B8055. We recently moved to LDAPS, however some of the copiers will not find a domain controller and we can't figure out why. 2 of the 5 work fine (and, oddly, those 2 are in the same office) The Altalink works fine and has the same configuration, but is in the same office as one of the non-functional workcentres. The altalink is in Site1 (10 subnet), the 2 working workcenters are Site2 (20 subnet), and the others are sites 3 (30 subnet) and 4 (40 subnet). We have DC's in each site (matching third octet) but also DC's at our HQ (50 subnet). I'll indicate the failed binds to a dc with -, and a successful bind with a +.
So we don't think it's the network at a site because the working ones are able to bind out of network and other copiers on the "non-working" sites bind successfully. We can't correlate firmware, we can't correlate against a specific DC. The accounts are all the same and we're not validating the LDAPS certificate. I CAN make the "broken" ones work by pointing them at port 389 instead of 636, however even after selecting SSL for LDAP the domain controller registers an insecure LDAP bind.
We are stumped. Any thoughts or troubleshooting help is appreciated.