The global address book in Apple Mail provided by Exchange already contains all members of TU Dresden. Please configure the LDAP directory only to find people from other universities and institutions in the DFN. It can currently only be used as an address book:
Apple Mail stores all certificates in the central "Keychain Access" of macOS. It cannot yet automatically access the certificates from the LDAP directory. Therefore, have your contact send you a signed email. The certificate is then automatically saved in the Keychain Access.
The following describes the configuration of Apple Mail for the integration of the DFN PKI LDAP directory service.
Name: DFN PKI LDAP
Search range: o=DFN-Verein, c=DE
Range: Subtree
Server: ldap.pca.dfn.de
Port: 636
Use SSL
Identification: None