The maps client certificates to user entries by mapping the values of attributes contained in the certificate subject to attributes contained in user entries. 1.3.6.1.4.1.26027.1.2.84 ds-cfg-subject-attribute-to-user-attribute-certificate-mapper ds-cfg-certificate-mapper org.opends.server.extensions.SubjectAttributeToUserAttributeCertificateMapper Specifies a mapping between certificate attributes and user attributes. Specifies a mapping between certificate attributes and user attributes. Each value should be in the form "certattr:userattr" where certattr is the name of the attribute in the certificate subject and userattr is the name of the corresponding attribute in user entries. There may be multiple mappings defined, and when performing the mapping values for all attributes present in the certificate subject that have mappings defined must be present in the corresponding user entries. 1.3.6.1.4.1.26027.1.1.315 ds-cfg-certificate-subject-attribute-mapping Specifies the set of base DNs below which to search for users. Specifies the base DN(s) that should be used when performing searches to map the client certificate to a user entry. If no values are provided, then the server will search below all public naming contexts. The server will perform the search in all public naming contexts. 1.3.6.1.4.1.26027.1.1.313 ds-cfg-certificate-user-base-dn