I ran into this myself. Either go grab the certificate from your DC or just add TLS_REQCERT never to the /etc/ldap/ldap.conf file and restart apache.