On Wed, 2015-08-26 at 12:02 -0700, Robert Brooks wrote:
> I believe we are looking to set TLS_REQUIRE_CERT to hard here...


Thanks for your patch but no, the setting of LDAP_OPT_X_TLS is
intentional. It is used to specify an ldaps:// connection (even if no
ldaps:// URL is specified and may be required for some LDAP libraries).

It is a bit weird that LDAP_OPT_X_TLS_HARD is used as a value for
LDAP_OPT_X_TLS but seems intentional:

