I am new to both and want to understand a little better how the certificate exchange works. If the server is providing a certificate, does the client need anything stored locally ? ,or does the server provide everything needed during the handshaking ? Along the same lines - is capath required if the server is providing a certificate ? Is the certificate validated automatically in perl ldap, or do I need to validate the certificate myself ? Very nooby questions, but I've never worked with this stuff before. Everything else looks pretty simple. Any information on how this works is appreciated. Thanks