Re: SSL certificates, kerberos keytabs, and load balancing

>> cert (ldapX.stanford.edu).  If I use a different cert for the server
>> (ldap.stanford.edu), I get a host name mismatch.  So you'll have to
>> use hardware load balancing.  I plan to test that with Stanford's
>> directory servers in the future, but that is a future project. ;)

>To solve the host mismatch problem in certificates you may addionally
>use the attribute subjectAltName, i.e.
>subjectAltName=commonName: ldap.example.com