Per
http://docs.sun.com/db/doc/806-4077/6jd6blbe5?a=view#ldapsecure-66
Note -
In order to use TLS for the Solaris LDAP naming service, the directory server must use the default ports, 389 and 636, for
LDAP and SSL, respectively. If your directory server does not use these ports, you cannot use TLS at this time.
Request for enhancement to allow the support of other ports instead
of 636/389.
This restriction makes the assumtion that all customers who plan to
migrate to native ldap in a secure environment plan to
use a single instance of DS on the machine which in many instances
is completely not true. It minimizes the scaleability of the ldap
server by imposing this restriction.