Microsoft Active Directory uses the UnicodePwd instead of the more common userPassword unless you have Enable UserPassword in Microsoft Active Directory.
All Active Directory Domain Controllers automatically enroll for domain controller certificate and utilize it for secure LDAP communications if Active Directory integrated Microsoft Certificate Server is deployed within the Forest.
As long as you deployed Microsoft Certificate Server in Active Directory integrated mode, then you don't need to do anything else on Active Directory side, all domain controllers will use SSL on port 636.