ok thanks. I added the tls options and the mutual TLS authentication works without ldaprc file. I m not sure that SASL EXTERNAL authentication works and it remains to configure the proxy to use the cn of its certificate instead of transmitting the client bind.