it's not certainly answer for my questions.
More or less I know how to configure SSL and LDAP.. but the problems are:
* get it work with wildcard certificate
* weak server ephemeral dh_key error
* if both can't be fixed I prefer to configure ssl on a reverse proxy, with http only enabled on SCC. But then I noticed that AD authentication for SCC stops working when using http.
I'm not sure what for you make some changes on plugins?
/fast/cfikany/SCC/SCC-3_2/plugins/ASEMAP
and
/fast/cfikany/SCC/SCC-3_2/plugins/DAMAP
and
/fast/cfikany/SCC/SCC-3_2/plugins/SCCMAP
vi agent-plugin.xml