https://bugs.openldap.org/show_bug.cgi?id=10065
--- Comment #4 from Howard Chu hyc@openldap.org ---
The LDAP clients would expect the "PLAIN" and "EXTERNAL" mechanisms to be available after authenticating with TLS to the LDAP proxy.
LDAP clients do not use SASL/PLAIN. See RFC4513 section 5.2.1.