CN in certificate and probably other user names are not properly escaped in LDAP search
Marking as private due to the nature of this but it does not look like the searches are ever sent to the LDAP server in this case.
User's certificate CNs have this format: CN=Firstname Lastname (keyword)
The parentheses there result in this log entries:
Jul 9 14:28:11 fw01 php-fpm: /diag_authentication.php: Search resulted in error: Bad search filter
Jul 9 14:28:11 fw01 php-fpm: /diag_authentication.php: ERROR! Either LDAP search failed, or multiple users were found.
The parentheses (and possibly other characters) probably need to be escaped before submitting to LDAP.