$ openssl s_client -connect server:636 -showcerts
$ ldapsearch -x -H "ldaps://server:636" -D 'uid=$UUID,dc=example,dc=com' -W
| BASE dc=example,dc=com | |
| URI ldaps://ldap-master.example.com:636 | |
| TLS_REQCERT never | |
| TLS_CACERT /etc/openldap/cacerts/cacert.crt | |
| TLS_CACERTDIR /etc/openldap/certs |