On Oct 27, 2011, at 2:27 PM, Daniel Qian wrote: > why don't you simply try > > TLS_CACERT /etc/pki/nssdb/<filename> > instead of > > > TLS_CACERTDIR /etc/pki/nssdb Because the cert isn't in a text file; it's in the NSS database. -- Braden McDaniel e-mail/Jabber IM: braden@endoframe.com http://endoframe.com