Hi Susan, yes it is. Below you can see my /etc/openldap/ldap.conf # HOST ldapserver BASE dc=example,dc=com TLS_REQCERT allow TLS_CACERT /etc/openldap/cacerts/cacert The openssl command Mark pointed to works fine. From that output I grabbed the CAcert and stored it the file I'm referencing in the /etc/openldap/ldap.conf I'm wondering if the certificate I created is correct. Should the cn in the certificate have the hostname as value? I guess it should or not? Thanks again, Jo -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.fedoraproject.org/pipermail/389-users/attachments/20060109/97ba23b5/attachment.html