When using LDAP over SSL in Strategy 2019, authentication may fail with the following error:
LDAP Server error (-1): Can't contact LDAP server.
One possible cause for this issue is due to the inability of the Intelligence Server to read the SSL certificate(cacert.pem). Even with the correct path specified in the Intelligence Server Configuration > LDAP > Server, the certificate will not be read due to a regression within Strategy 2019 that will fail to compose the path to the certificate.
This issue is fixed in Strategy 2019 Update 1. Upgrade to Strategy 2019 Update 1 or later to take advantage of the fix.
As a workaround, the certificate(cacert.pem) can be placed within the working directory of the Intelligence Server <MSTR_HOME_PATH>/Intelligence Server(eg; /var/opt/MicroStrategy/IntelligenceServer).