Hi,
Based on my understanding, it is a cert on the LDAPS server (Domain Controller) for server authentication issued by the trusted CA server.
When request cert for server authentication we can use the Kerberos template. Or we can create your own or use one of the existing templates that has Server Authentication as a purpose, such as Domain Controller Authentication, Domain Controller, Web Server, and Computer.
Important: You should be planning to have only one certificate on each LDAP server (i.e. domain controller or AD LDS computer) with the purpose of Server Authentication.
For more details, you can refer to the following link:
https://social.technet.microsoft.com/wiki/contents/articles/2980.ldap-over-ssl-ldaps-certificate.aspx
If i misunderstand you, feel free to let me know.
Best Regards,