The maps client certificates to user entries by looking for the certificate subject DN in a specified attribute of user entries. 1.3.6.1.4.1.26027.1.2.84 ds-cfg-subject-dn-to-user-attribute-certificate-mapper ds-cfg-certificate-mapper org.opends.server.extensions.SubjectDNToUserAttributeCertificateMapper Specifies the attribute in which to look for the subject DN. Specifies the name or OID of the attribute whose value should exactly match the certificate subject DN. 1.3.6.1.4.1.26027.1.1.312 ds-cfg-certificate-subject-attribute-type Specifies the set of base DNs below which to search for users. Specifies the base DN(s) that should be used when performing searches to map the client certificate to a user entry. If no values are provided, then the server will search below all public naming contexts. The server will perform the search in all public naming contexts. 1.3.6.1.4.1.26027.1.1.313 ds-cfg-certificate-user-base-dn