Every run died in the same place. My Ludus lab runs AD CS on the Domain Controller, so the CA callback authenticated as the DC's machine account: a server trust account rather than an ordinary workstation trust account.
Impacket's rogue SMB NetLogon path and CertiGhost's LDAP validation both set ParameterControl to K (0x800), but not E (0x20), the bit Microsoft defines for a Domain Controller.
STATUS_NOLOGON_SERVER_TRUST_ACCOUNT, every time.