Below is the script I created to manage this certificate creation steps.... # cat DsCreateCert #!/bin/ksh -a # If the following flag is set to 1, certutil will be used. If set to 0, openssl will be used flagUseCertutil=1 # DER: a binary format # PEM: base-64 encoded DER format with header and footer # certutil: Default is DER. For PEM, use "-a" # openssl: Default is PEM. For DER, use "-inform DER" and/or "-outform DER" flagUseDer=0 flagUsePem=1 openSslPath=/usr/ local /ssl SSL= ${openSslPath} /bin/openssl CERT=/usr/sfw/bin/certutil PK12=/usr/sfw/bin/pk12util # Fake CA (Certification Authority) database caDbPath=/store/bnz/cacertdb caId="ca-" caDbId="-d ${caDbPath} -P ${caId} " # LDAP server certification database serverRoot="/var/ldap_data_files/ds" serverDbPrefix="slapd-" serverDbPath=" ${serverRoot} / alias " serverDbId=&qu...