Hi, How would this be set at the client end? Ie it seems a bit silly to have ldap.conf like this, ====== URI ldap://vuwunicvfdsm001.vuw.ac.nz/ BASE dc=vuw,dc=ac,dc=nz TLS_CACERTDIR /etc/openldap/cacerts ssl start_tls ====== As if I lose the master (I assume) the slave (vuwunicvfdss001) wont be queried.... Regards Steven Jones