Larry, >For e-mail certificates, can't you use the domain from >the internet e-mail address to point you to a DNS server >And can't that in turn point you to the correct LDAP directory. One can certainly look up the user's DNS server based on e-mail address, but we don't have a record format in the DNS that points to an LDAP directory as a result. One could define such a record type, though. Steve