diff --git a/config/config.exs b/config/config.exs
index 8544dcc0d8a599501d06f8b1bd50c3509881eab9..1ed330df2f834e72cad8f3156c18f7b00473f85d 100644
--- a/config/config.exs
+++ b/config/config.exs
@@ -361,6 +361,8 @@ config :pleroma, :ldap,
   port: String.to_integer(System.get_env("LDAP_PORT") || "389"),
   ssl: System.get_env("LDAP_SSL") == "true",
   sslopts: [],
+  tls: System.get_env("LDAP_TLS") == "true",
+  tlsopts: [],
   base: System.get_env("LDAP_BASE") || "dc=example,dc=com",
   uid: System.get_env("LDAP_UID") || "cn"
diff --git a/docs/config.md b/docs/config.md
index 8d6770959813eeca6ffc62936a441ffb0df7d8db..7052b1eb4ccf0d52cfff4cff84633d734d18d466 100644
--- a/docs/config.md
+++ b/docs/config.md
@@ -329,13 +329,21 @@ config :auto_linker,
 ## :ldap
+Use LDAP for user authentication.  When a user logs in to the Pleroma
+instance, the name and password will be verified by trying to authenticate
+(bind) to an LDAP server.  If a user exists in the LDAP directory but there
+is no account with the same name yet on the Pleroma instance then a new
+Pleroma account will be created with the same name as the LDAP user name.
 * `enabled`: enables LDAP authentication
 * `host`: LDAP server hostname
 * `port`: LDAP port, e.g. 389 or 636
-* `ssl`: true to use SSL
+* `ssl`: true to use SSL, usually implies the port 636
 * `sslopts`: additional SSL options
+* `tls`: true to start TLS, usually implies the port 389
+* `tlsopts`: additional TLS options
 * `base`: LDAP base, e.g. "dc=example,dc=com"
-* `uid`: attribute type to authenticate the user, e.g. when "cn", the filter will be "cn=username,base"
+* `uid`: LDAP attribute name to authenticate the user, e.g. when "cn", the filter will be "cn=username,base"
 ## Pleroma.Web.Auth.Authenticator
diff --git a/lib/pleroma/web/auth/ldap_authenticator.ex b/lib/pleroma/web/auth/ldap_authenticator.ex
index 56f2f5aed5a860699f4df059d4031bb052f7e09a..88217aab84dd533e632c2818bd823d706efcdcb7 100644
--- a/lib/pleroma/web/auth/ldap_authenticator.ex
+++ b/lib/pleroma/web/auth/ldap_authenticator.ex
@@ -60,22 +60,23 @@ defmodule Pleroma.Web.Auth.LDAPAuthenticator do
     case :eldap.open([to_charlist(host)], options) do
       {:ok, connection} ->
         try do
-          uid = Keyword.get(ldap, :uid, "cn")
-          base = Keyword.get(ldap, :base)
-          case :eldap.simple_bind(connection, "#{uid}=#{name},#{base}", password) do
-            :ok ->
-              case User.get_by_nickname_or_email(name) do
-                %User{} = user ->
-                  user
-                _ ->
-                  register_user(connection, base, uid, name, password)
-              end
-            error ->
-              error
+          if Keyword.get(ldap, :tls, false) do
+            :application.ensure_all_started(:ssl)
+            case :eldap.start_tls(
+                   connection,
+                   Keyword.get(ldap, :tlsopts, []),
+                   @connection_timeout
+                 ) do
+              :ok ->
+                :ok
+              error ->
+                Logger.error("Could not start TLS: #{inspect(error)}")
+            end
+          bind_user(connection, ldap, name, password)
@@ -86,11 +87,31 @@ defmodule Pleroma.Web.Auth.LDAPAuthenticator do
+  defp bind_user(connection, ldap, name, password) do
+    uid = Keyword.get(ldap, :uid, "cn")
+    base = Keyword.get(ldap, :base)
+    case :eldap.simple_bind(connection, "#{uid}=#{name},#{base}", password) do
+      :ok ->
+        case User.get_by_nickname_or_email(name) do
+          %User{} = user ->
+            user
+          _ ->
+            register_user(connection, base, uid, name, password)
+        end
+      error ->
+        error
+    end
+  end
   defp register_user(connection, base, uid, name, password) do
     case :eldap.search(connection, [
            {:base, to_charlist(base)},
            {:filter, :eldap.equalityMatch(to_charlist(uid), to_charlist(name))},
            {:scope, :eldap.wholeSubtree()},
+           {:attributes, ['mail', 'email']},
            {:timeout, @search_timeout}
          ]) do
       {:ok, {:eldap_search_result, [{:eldap_entry, _, attributes}], _}} ->
@@ -110,7 +131,9 @@ defmodule Pleroma.Web.Auth.LDAPAuthenticator do
             error -> error
-          _ -> {:error, :ldap_registration_missing_attributes}
+          _ ->
+            Logger.error("Could not find LDAP attribute mail: #{inspect(attributes)}")
+            {:error, :ldap_registration_missing_attributes}
       error ->