Thanks Richard, but this howto explain how to to match DN certificate to LDAP entry... my problem is; i don't want to have a corresponding entry in LDAP directory... I want to be identify only by the DN in the certificate, and match some ACL.. that all. No need to have an entry in the LDAP. If it's possible in DS... Yann > Does this help - http://directory.fedora.redhat.com/wiki/Howto:CertMapping