The maps client certificates to user entries by looking for the certificate subject DN in a specified attribute of user entries. ds-cfg-subject-dn-to-user-attribute-certificate-mapper ds-cfg-certificate-mapper org.opends.server.extensions.SubjectDNToUserAttributeCertificateMapper Specifies the attribute in which to look for the subject DN. Specifies the name or OID of the attribute whose value should exactly match the certificate subject DN. ds-cfg-subject-attribute Specifies the set of base DNs below which to search for users. Specifies the base DN(s) that should be used when performing searches to map the client certificate to a user entry. If no values are provided, then the server will search below all public naming contexts. The server will perform the search in all public naming contexts. ds-cfg-user-base-dn