In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
https://lists.debian.org/debian-lts-announce/2023/01/msg00027.html
https://lemonldap-ng.org/download
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2250