https://bugs.openldap.org/show_bug.cgi?id=8610
--- Comment #4 from Michael Ströder michael@stroeder.com --- And still there is no standard which defines a decent TLS domain name check for SRV RRs with well-defined subjectAltName values to prevent MITM attacks.
See also: https://tools.ietf.org/html/rfc6125#section-3