In order to use the ldapclient tools with -ZZ option to force encryption you must have the following in ~/.ldaprc tls_cacert /path/to/cacert.pem having it in ldap.conf is not correct for these tools. GREG -- Greg Matthews iTSS Wallingford 01491 692445