https://bugs.openldap.org/show_bug.cgi?id=9277
--- Comment #3 from Michael Ströder michael@stroeder.com --- (In reply to Howard Chu from comment #1)
If you suspect that TLS is the cause, then it should be simple to verify by trying to reproduce the issue with TLS disabled.
In Æ-DIR nothing works without TLS. Unencrypted connections are blocked. Also slapd uses the server cert as client cert for replication, thus there's a larger TLS ServerHello.
At least when simply disabling TLS for syncrepl slapd hits "Confidentiality required" but stops going into a loop.