Please send me a copy of the full debug output, not just the TLS messages. There should specifically be a call to ldap_dn2bv() with your certificate's DN being logged in normalized LDAP format. Which version of SASL library are you using?
TLS certificate verification: depth: 0, err: 0, subject: /C=DE/ST=Baden-W\xFCrttemberg/L=T\xFCbingen/O=DAASI International GmbH/CN=Norbert Klasen/Email=norbert.klasen@daasi.de, issuer: /C=DE/O=DAASI International GmbH/OU=DAASI CA/Email=ca@daasi.de
attributetype ( 1.2.840.113549.1.9.1 NAME 'pkcs9email' DESC 'RFC2459: legacy attribute for email addresses in DNs' EQUALITY caseIgnoreIA5Match SUBSTR caseIgnoreIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{128} )
-- Norbert Klasen, Dipl.-Inform. DAASI International GmbH phone: +49 7071 29 70336 Wilhelmstr. 106 fax: +49 7071 29 5114 72074 Tübingen email: norbert.klasen@daasi.de Germany web: http://www.daasi.de