The maps client certificates to user entries by looking for the certificate subject DN in a specified attribute of user entries. ds-cfg-subject-dn-to-user-attribute-certificate-mapper ds-cfg-certificate-mapper org.opends.server.extensions.SubjectDNToUserAttributeCertificateMapper Specifies the name or OID of the attribute whose value should exactly match the certificate subject DN. ds-cfg-subject-attribute Specifies the base DNs that should be used when performing searches to map the client certificate to a user entry. The server will perform the search in all public naming contexts. ds-cfg-user-base-dn