$^(*!$!^&(!/. I had a huge response all typed up and this forum blew up the answer. Lost my submittion.
I will summarize:
ENABLE DEBUGGING. It was not until I enabled debugging for ranger that, when I got an error similar to yours, I uncovered that I needed to get my AD certificate into the truststore
Note, ranger has TWO truststores. One for the user sync, the other for ranger itself logging in the UI.......................
check these, and that your AD certificate is in the keystore mentioned:
ranger.usersync.truststore.file
ranger.https.attrib.keystore.file