The intermediate CA certificate was not included in the certificate file used by Samba, so LDAP/TLS connections would fail with a trust validation error.
*dc2.pyrocufflink.blue* acts as a second Active Directory Domain Controller with *samba*.