I noticed that the server was extracting the PEM files from the keystore by default and was wondering if there was really any use for this being on by default.

The relevant setting is nsslapd-extract-pemfiles.



