Hi Dont know how to reply on same thread.
but thank for quick reply.
its case sensitive. so I created the cert file and i put that one into client , and i configured as documentated
/etc/openldap/ldap.conf
URI ldap://ldap-2.fosiul.lan/ BASE dc=fosiul,dc=lan TLS_CACERTDIR /etc/openldap/cacerts/ TLS_REQCERT allow #TLS_CACERT /etc/openldap/cacerts/cacert.asc
and in /etc/ldap.conf base dc=fosiul,dc=lan uri ldap://ldap-2.fosiul.lan/ ssl start_tls tls_cacertdir /etc/openldap/cacerts/
#TLS_CACERT /etc/openldap/cacerts/cacert.asc pam_password md5
and i can see it created another file in /etc/openldap/cacerts/ directory like ths 5be5959f.0 ds-ca.crt
and when i do like this
id usrname
it does not find the user and i dont see any error in /var/log/message
so its like its connecting to ldap. .but it does not get any information
do i have to say Cn="Directory Manager" some where in ldap.conf file ??
thanks for your help.
Fosiul
but in clients , log file