TLS - verifying and requiring its use

A couple of TLS-related questions:

1. What slapd debug level would tell me whether or not TLS is being used
for a particular connection?  I am trying to figure out whether a
particular client application is using TLS.

2. What are the right slapd.conf settings to -require- clients to use
TLS?  I was not able to figure this out from looking at the slapd.conf
man page.  I am currently using openldap 2.2.23.  I know it is a little
old and I plan to upgrade soon, but for now, this is my target version
for getting required TLS working.