Use STARTTLS on a plain LDAP connection, usually on port 389.
Verify the TLS certificate of the server.