Howard Chu wrote, on 11. apr 2007 08:11:
[...]
So, if the goal is to use certificate-based authentication, then the
solution is to generate a proper certificate without any usage
restrictions on it, or one that says it can be used for client
authentication.
If the goal isn't to use certificate-based authentication, then some of
your advice is correct.
It seemed to me that OP was simply trying to establish an encrypted
connection, as so many have done in the past and slapd was barfing on a
missing client cert.