that makes sense, I could not find LDAP_OPT_X_TLS in the ldap_set_option man page, so it looked odd!

My other question next question is, why aren't other tls options set in myldap.c, for example tls_ciphers, tls_cacert etc? I see them set in cfg.c...



> I believe we are looking to set TLS_REQUIRE_CERT to hard here...


Thanks for your patch but no, the setting of LDAP_OPT_X_TLS is
intentional. It is used to specify an ldaps:// connection (even if no
ldaps:// URL is specified and may be required for some LDAP libraries).

It is a bit weird that LDAP_OPT_X_TLS_HARD is used as a value for
LDAP_OPT_X_TLS but seems intentional:

