tls private key


I am setting up my sync repl to use certificates, my problem is I don't
want to leave my private key for the server un encrypted.

the file pointed to by TLSCertificateKeyFile is is just read at slapd
load up time, ie can i unencrypt  the file start slapd and then remove
the un encrypted file ?


