https://bugs.openldap.org/show_bug.cgi?id=8753
--- Comment #11 from Ondřej Kuzník ondra@mistotebe.net --- How about https://git.openldap.org/ondra/openldap/-/commit/e020f3ba26fd6d42ce0f91299b7...
It should be analogous to HTTP Public Key Pinning, that's why it's working with keys, not certificates.