https://bugs.openldap.org/show_bug.cgi?id=10065
--- Comment #1 from Quanah Gibson-Mount quanah@openldap.org --- Pretty much everything in this report is incorrect and is not how things function. I suggest reading the slapd.conf(5) man page in better detail.
I would note that the EXTERNAL SASL mechanism has nothing to do with cyrus-sasl.
An olcSecurity: tls=X would mandate TLS encryption on the connection, i.e., it would apply to simply binds as well as SASL mechanisms.