client TLS certificates and SASL

I added blindly code to HEAD to (again) fix a crash (in -lldap)
due to lack of SASL context for enabling EXTERNAL after
ldaps:// certificate assertion.  Blindly in the sense that I
currently don't have an environment available to test the code.
If you have, please test as I need some confirmation that the
changes work before bringing them into REL_ENG_2.