https://bugs.openldap.org/show_bug.cgi?id=10065
--- Comment #20 from sean@teletech.com.au --- (In reply to Ondřej Kuzník from comment #18)
You choose what CAs are trusted to issue client certificates and this is independent from the CAs you trust for server certs. Could that be the trust anchor you're missing?
Yeah, I understand that - and I don't use the ca bundle for that very reason, just the single CA that I need to validate my clients, but it still isn't a very exclusive club. That CA is Let's Encrypt.