The configuration I created for them was straight LDAP on the pfsense side originally, and it failed. I was assured by the second party they were NOT running LDAPS, and that I must be typing the account credentials wrong. Once I loaded the ldap verbose logging tool in pfsense, I suspected that LDAPS was in play, and explained that we needed to exchange root certificates and that conversation hit a brick wall fast. I would always prefer secure setups, but my issue is that I don't always work with people that understand their own networks. Every now and then I have to tell people (nicely) that they are in fact running something they think they aren't, and I always want good technical information to back me up when I do .
Thanks again for the prompt reply, this was a big help.