LDAPS is deprecated in OpenLDAP, as it has no formal standard, but it is fully supported in Active Directory, and it may be required in some environments, specifically because of this potential issue, that nothing in basic LDAP prevents clients from authenticating unencrypted.