If you do not have access to the certificate for the LDAP server, this method still provides you with encrypted communications. You must ensure that you are communicating with the intended LDAP server, which you provided in your URL. If that gets maliciously redirected, then you could be talking to a different server.