If, when trying to start ldap, you get this error in the logs:

slapd[5053]: main: TLS init def ctx failed: -1

The problem is the owner/group of the ssl certificate. The certificate that slapd uses must be owned by ldap and in group ldap.