i am seeing the same behavior (tls is not functioning) with sudo-ldap_1.6.9p17-2_i386.deb.
[21:15:17 t...@jenna:archives]$ sudo ls / LDAP Config Summary =================== uri ldap://host1.oma.example.net ldap://host2.oma.example.net ldap_version 3 sudoers_base ou=sudoers,ou=oma,dc=example,dc=net binddn (anonymous) bindpw (anonymous) bind_timelimit 15000 timelimit 15 ssl start_tls tls_checkpeer (yes) tls_cacertfile /etc/ssl/certs/ca.crt =================== sudo: ldap_initialize(ld, ldap://host1.oma.example.net ldap://host2.oma.example.net) sudo: ldap_set_option: debug -> 0 sudo: ldap_set_option: ldap_version -> 3 sudo: ldap_set_option: tls_checkpeer -> 1 sudo: ldap_set_option: tls_cacertfile -> /etc/ssl/certs/ca.crt sudo: ldap_set_option: timelimit -> 15 sudo: ldap_set_option(LDAP_OPT_NETWORK_TIMEOUT, 15) sudo: ldap_start_tls_s(): Connect error [21:10:52 t...@jenna:archives]$ dpkg -I sudo-ldap_1.6.9p17-2_i386.deb new debian package, version 2.0. size 188332 bytes: control archive= 2525 bytes. 33 bytes, 2 lines conffiles 642 bytes, 18 lines control 1674 bytes, 25 lines md5sums 1831 bytes, 64 lines * postinst #!/usr/bin/perl 170 bytes, 7 lines * postrm #!/bin/sh 260 bytes, 11 lines * prerm #!/bin/sh Package: sudo-ldap Source: sudo Version: 1.6.9p17-2 Architecture: i386 Maintainer: Bdale Garbee <bd...@gag.com> Installed-Size: 460 Depends: libc6 (>= 2.7-1), libldap-2.4-2 (>= 2.4.7), libpam0g (>= 0.99.7.1), libpam-modules Conflicts: sudo Replaces: sudo Provides: sudo Section: admin Priority: optional Description: Provide limited super user privileges to specific users Sudo is a program designed to allow a sysadmin to give limited root privileges to users and log root activity. The basic philosophy is to give as few privileges as possible but still allow people to get their work done. . This version is built with LDAP support. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org