In order to be able to set some properties in AD (using SSL) one of two
things needs to be true;
1.) The machine making the connection needs to be a member of that
GC/DC's domain, OR
2.) A cert from the target GC/DC needs to be created and installed on
the machine making the connection. (see links) hope this helps.
247078 How To Enable Secure Socket Layer (SSL) Communication over LDAP
for
http://support.microsoft.com/?id=247078
321051 How to enable LDAP over SSL with a third-party Certification
Authority
http://support.microsoft.com/?id=321051
254610 System Event ID 36876 When Using LDAP SSL Query of the Active
Directory
http://support.microsoft.com/?id=254610
273753 Description of the LDAP API over SSL requirements
http://support.microsoft.com/?id=273753
883639 An LDAP connection to a CA or an LDAP bind to a CA is completed
http://support.microsoft.com/?id=883639