So, I switched from ldaps to ldap, and suddenly, the synchronozation worked.Ok that is bad, because that means your SSHA is going over a unencrypted connection and afaik this ssha can be (easily?) brute forced with something like john the ripper (only tried one account of mine, so could be not as bad as I write)
-- Jordan Brown, Oracle ZFS Storage Appliance, Oracle Solaris