As far as I can tell everything is fixed, on my end, but YOU MAY NEED TO UPDATE your client.
A) The proxy wasn't forwarding 400/500 errors. It was 404-ing them instead. Fixed
B) Multiple issues with SSL certificate updates.
New Intermediate and Root certificates.
If you were manually specifying the ssl certificates to use in your client previously, you'll need to delete them (the new intermediates are more well known) or manually up date to including these (if you have old versions of openssl):
New version of passport-lds-connect
If you're using passport-lds-connect, you MUST UPDATE to version 1.2.0.
The previous version manually includes the outdated root and intermediate certs which will probably cause a failure to connect.