RFC: Handling of certificates in Debian

Hi *, 

Now that the LDAP packages support TLS I would like to do the next 
step: Get a sane debconf interface on first installation to setup
the directory and generate the TLS key and certificate.

But now I wonder if there is some established procedure for doing 
so. I know many users will not have a key signed by verisign or
thawte/whatever but instead sign them themselves. 

I wonder how to support both modes and if I should have the installation
do it all automatically for them. 

And input appreciated


