thank you, that seems the only way, since pfsense isnt supporting SASL.
tried yesterday also with Apache Directory Studio
connection is accepted with StartTLS (no SASL), which doesnt work in pfsense .
[image: 1720788012451-f70705f8-df66-484e-9761-4dd8f906e341-grafik.png]
and
[image: 1720788201961-df09bfed-e607-47a1-9afe-b9a43e917279-grafik.png]
this is getting me really confused.
anyway
i will try to export the CA and do it your way,
(was unsuccessful today, to find out how/where to extract it from the synology. the only thing i got was the certificate, no CA )
thank your for your help, i will report back how it went (in about two weeks, have to pause this project).