Of course one trick is to make sure your LDAP client can "Trust All"... otherwise, you may need to import the self-signed certificate for the ldap server into the truststore for your client. OpenDJ generates self signed certificates during installation and stores them in /opt/opendj/config if I'm remembering right.