I still haven't found how to have tls working with client certificate verification... Is it required for this to use SASL EXTERNAL ? I want to try SASL EXTERNAL, but I need some clarification... How does the server map the client certificate with the dn used to authenticate ? Where do the certificates have to be stored ? (and do they have to be stored ? ) if anyone can help me... very thx Francois Beretti