OpenLdap/SASL/TLS ...

What is the best way to get all the traffic between an openldap server and
an openldap client encrypted?
If this involves using SASL, does it have to be configured with kerberos? if
it does not require kerberos, how do I get it working?



