Same problem here:
If I use the cn=config style, proxy authorization works directly after
If I reboot the slave server the authorization fails to work and the
bindmethod switches from SASL/GSSAPI to SIMPLE.
If I delete the configuration directory /etc/ldap/slapd.d and use a
simple /etc/ldap/slapd.conf and make the same configuration the old way
everything keeps working after reboots.
So I think there is a Problem while loading the cn=config configuration.
Something in this area should have been fixed in master code; some fixes
may have been released in 2.4.26. Can you indicate what version you're
using? In case you're using the latest, can you test with master code?