I don't really have any idea then, sorry. You might check on the server for any useful logs. You might also consider trying to do the same thing using ldp.exe and its StartTLS menu option to see if you can get it to work that way or get some additional error details.
Otherwise you might be stuck putting in a ticket to Microsoft on this one.