https://bugs.openldap.org/show_bug.cgi?id=9318
--- Comment #4 from dar@xoe.solutions --- Maybe it would be good to put a debug message accordingly, though:
Debug0( LDAP_DEBUG_ANY, "TLS: unable to validate host based on subject alternative names falling back to subject name...\n" );
The current error message (wrongly) suggests that the only option is common name based host validation