> Changes based upon your patch have been committed to HEAD.
> Please test.

Built the latest HEAD checkout.  It appears to work:

/usr/local/bin/ldapsearch -Q -LLL -ZZZ -h ldap3.stanford.edu uid=quanah 
dn: uid=quanah,cn=Accounts,dc=Stanford,dc=edu
suMailDrop: quanah@quanah.pobox.stanford.edu

dn: suRegID=85e49978f61311d2ae662436000baa77,cn=People,dc=Stanford,dc=edu

/usr/local/bin/ldapsearch -Q -LLL -ZZZ -h ldap3 uid=quanah sumaildrop
ldap_start_tls: Connect error (-11)
        additional info: TLS: hostname does not match CN in peer certificate



