Pierangelo Masarati writes:
-ZZ should be deprecated, and -Z should simply and strictly require StartTLS.
Good point. Except then people who are used to new clients will make insecure connections when using old clients. Maybe -Z should be an error instead...
What I'd really really like to do is throw away all the options, rename the programs, and start over. This time with the same option names in ldap tools, slap tools, and slapd itself. Goes with the someday-in-the-future library rewrite, I suppose.