RE: Doubt regarding the cert that signs the CRL

Nice summary. Just a note, you can set the CA cert in /etc/ldap.conf,
to save yourself one step in all the other configs.

> I can tell You my practice. I post this kind of tutorial on LDAP/TLS
> for all people interested. You may skip several parts.