On the console the customer sees :
FATAL (05/09) 12:10:51 [com.stoneware.service.DirectoryManager]: Unable to verify/extend schema.
javax.naming.CommunicationException: simple bind failed: 10.1.1.17:636 [Root exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target]
Go into the 8090 console using your secondary username / password. The secondary username / password allows the admin to get into the 8090 console when it is unable to talk to Microsoft Active Directory.
Once in 8090 console, go to Directory Services, click on the import SSL button at the bottom. Shut down webnetwork, start it back up and verify that it is now able to talk to Active Directory.