AD / LDAP UID vs UserPrincipalName

Another less secure solution is disable ssl requirement, like documented here

https://wiki.samba.org/index.php/Updating_Samba#New_Default_for_LDAP_Connections_Requires_Strong_Authentication

Edit /var/lib/machines/nsdc/etc/samba/smb.conf then restart samba nsdc service

 systemctl -M nsdc restart samba

IIRC in some past discussion a Zentyal user told me that AD LDAP can be browsed anonymously…