Subject: You cannot reach Active Directory (AD) on port 636 with the IP Address using LDP.exe
Author: authen
Posted on: 01/13/2009 09:41:55 PM
This problem occurs because on the client side the system compares the name stored in the certificate ("Subject" and "Subject Alternative Name" fields) with the name specified for the connection (here the IP address). As they don't match authentication fails and client get an error.
So, when you try to access the Active Directory with LDP.exe using SSL (LDAP over port 636), you cannot use the IP Address of the domain controller, you have to use the name (either host name or FQDN).
References: