However it looks like it might be a client issue after all, because I found out some clients can actually talk to the server through ldaps:// or STARTTLS, while others fail with "Can't contact ldap server". This is some weird breakage. Don't bother too much with this, I think I have to do some more experimentation. But thanks to all for the quick responses so far.
GnuTLS vs OpenSSL linked libraries? --Quanah -- Quanah Gibson-Mount Principal Software Engineer Zimbra, Inc -------------------- Zimbra :: the leader in open source messaging and collaboration