https://bugs.openldap.org/show_bug.cgi?id=9279
--- Comment #6 from Michael Ströder michael@stroeder.com --- (In reply to Michael Ströder from comment #4)
See also my inquiry to ietf-ldapext mailing list:
https://mailarchive.ietf.org/arch/msg/ldapext/jBnnQxBngfYUD8A2RLeI1tAVb5M
Neil's response is pretty clear:
https://mailarchive.ietf.org/arch/msg/ldapext/_J2wBksnlCYbemmf3bTanCDAXuA
No DER, just ASCII digits in a byte-sequence. Yes, it's legacy stuff.