I apologize, it seems that upgrading OpenLDAP client from 2.41 to 2.44 did the trick 9either known CA was not yet known in 2.41 or the key length has changed there). Best regards, olivier --