So, I just found about the update-ca-certificates command and /usr/share/ca-certificates folder.
The reason libnss_ldap didn't find CA certificate might be I didn't follow standard procedures.
(Fanny thing on slapd server machine, it found it without tls_cacertfile line, but on client machine it didn't.)
So, I just found about the update- ca-certificates command and /usr/share/ ca-certificates folder.
The reason libnss_ldap didn't find CA certificate might be I didn't follow standard procedures.
(Fanny thing on slapd server machine, it found it without tls_cacertfile line, but on client machine it didn't.)
I think I have to rewrite 1-5 altogether.