>Ok....aside from the smbldap-tools config stuff and the switches in the
>openldap files.....is there anything special I have to do to make TLS run?
> I have Net::LDAP installed.
Within /etc/openldap/slapd.conf you will find...

# The next three lines allow use of TLS for connections using a dummy test
# certificate, but you should generate a proper certificate by changing to
# /usr/share/ssl/certs, running "make slapd.pem", and fixing permissions on
# slapd.pem so that the ldap user or group can read it.
# TLSCACertificateFile /usr/share/ssl/certs/ca-bundle.crt
# TLSCertificateFile /usr/share/ssl/certs/slapd.pem
# TLSCertificateKeyFile /usr/share/ssl/certs/slapd.pem

So you need to uncomment those three TLS... lines and generate a 
certificate as recommended.  Then restart the ldap service.

