LDAP signing is not supported. If you do not want to install ADCS, even though it is cool for a lot of other stuff, you can add a self signed certificate. Then restart the NTDS service to have LDAPS on that domain controller. I use the few lines of powershell below to add and trust the certificate (had to remove my…