> For the setup you described, you'd probably want to use a > single certificate, signed with a CN of 'ldap.domain.example.com'. > > This will make it possible for your server cert CNs and > hostnames to match consistently, regardless of which machine > (nodo1 or nodo2) the clients end up talking to. > Uhm...I can try, but in that case, is it possible that I've a problem with replication ? Nodes use server ca with only difference....CN I maked 2 server CA with the same CA Thanks Alex -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.fedoraproject.org/pipermail/389-users/attachments/20060403/f961f034/attachment.html