The problem I have is I am on Fedora Core 4 and there is no CA.sh script like described in section 4.2
/etc/pki/tls/misc/CA
For a local CA, you will also want the line:
TLSCACertificateFile /path/to/your/cacert.pem
in your slapd.conf file. The error message you are getting indicates that you are not finding the CA for verification.
Jon Roberts www.mentata.com