You've told (or more accurately probably left) the IdP to use a locally configured trust anchor for the AD's TLS support and that file hasn't been created by you. That's the meaning of the reference to not being able to load ldap-server.crt buried in the Spring errors. -- Scott