>> 2) openLDAP software doesn't like them. (or maybe I've been doing
>> something wrong at that time...)

>Default behavior.  You can disable it, I don't remember how
>but it's documented in the Admin Guide under TLS.

I've found it a bit confusing at a time... This document actually got me going: