Use STARTTLS on a plain LDAP connection usually on port 389.
Verify the TLS cerificate of the server.