https://bugs.openldap.org/show_bug.cgi?id=10065
--- Comment #22 from sean@teletech.com.au --- (In reply to Howard Chu from comment #21)
Use slapo-autoca to create your own CA cert to manage your client certs.
I wasn't aware you had your own CA infrastructure. Thanks for bringing it up. It certainly deserves a mention in this context. I actually already have a private CA which I could use for LDAP, but I wanted my clients to have public CA certs on their front-facing ports. I could use private CA certs for the back facing ports but I think it's easier to just have the proxy.