LDAP clients can't connect to the LDAP service over SSL when the server uses a self-signed Domino server certificate
If the server that runs the LDAP service uses a self-signed Domino certificate, non-Notes LDAP clients can only perform LDAP searches over SSL if they first connect to the Domino server over SSL using a different protocol (for example HTTPS or IMAP). The client software then presents a warning dialog stating that the server's self-signed certificate is not issued by a trusted Certificate Authority and gives the users the option to accept the certificate. The users must accept the certificate before they can perform LDAP searches over SSL.

