SSL certificates, kerberos keytabs, and load balancing

> To solve the host mismatch problem in certificates you may addionally
> use the attribute subjectAltName, i.e. 
> commonName=ldap1.example.com
> subjectAltName=commonName: ldap.example.com

The actual syntax in OpenSSL is

Note this is an X.509v3 certificate extension, not an LDAP attribute.

