Use STARTTLS on a plain LDAP connection usually on port 389.
Verify the TLS cerificate of the server.
Leave the Bind DN empty if you want to do anonymous binding.
The user data in this database can be modified from within privacyIDEA.