SSL client certificate mapping?

I hadn't gotten any conclusive answers to some questions I asked last week, so I thought I'd ask them again:

In this message, I ask whether there's a way to take a certificate presented over an SSL session and map it programmatically to a DN:


In this message, I ask whether it's possible to specify a client-side certificate to use with OpenLDAP's ldapsearch command over SSL (as this can be done with Netscape's ldapsearch command):


I understand that some prefer the use of SASL EXTERNAL rather than SSL certificate-based authentication, but I still have a need to get SSL client certificates to work with OpenLDAP, and would greatly appreciate any insights people might have.