I found the previous post of someone else who faced the same problem I'm encountering, but I did not see a posted solution:
http://www.openldap.org/lists/openldap-technical/201310/msg00084.html
In /etc/openldap/ldap.conf, TLS_REQCERT is set to 'allow'.
I would like to leave this setting, but override it for a specific invocation of ldapsearch. I have attempted to do so by setting TLS_REQCERT in ~/.ldaprc and be setting the LDAPTLS_REQCERT environment variable. Neither has worked.
Interestingly, I _HAVE_ found that I can override TLS_CACERTDIR in either of those locations.
Is this a bug?
Andy