No. They should be syncing from FDS -> AD without SSL, but not the other way. This is related to your issue 2 below.
Other way around. Password sync AD -> FDS works without SSL. Password sync FDS -> AD requires SSL. AD will refuse to modify a password unless you connect via SSL. -- Fedora-directory-users mailing list Fedora-directory-users@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-directory-users