There is a bug with LDAP TLS in that LDAP doesn't know where the ca file are.
We have an open support ticket on this, and you can look at the bug report for more info.
https://bugzilla.zimbra.com/show_bug.cgi?id=43701
Suggest opening a support ticket with Zimbra directly, in the interim you can disable LDAP TLS on both servers by running the following as the zimbra user on both servers and then restarting Zimbra.
Code:
zmlocalconfig -e ldap_starttls_supported=1
At that point though, all the inter-server LDAP traffic is plain text, which may be a security risk depending on your infrastructure.
Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO
"Uptime. All the time."
477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678
proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting