openldap server and client switched to mozilla nss certdb since version 2.4.23. The ldap modules (server, client, ldap-users and groups) do not support this yet. An error is reported if cretificate field are (mis)used to enter the corresponding infromation. TLS protected access works as long as client verification is not requested by the server.