final LdapName dn = new LdapName(dnStr);
final SearchControls searchControls = new SearchControls();
searchControls.setSearchScope(SearchControls.OBJECT_SCOPE);
final String attrIDs[] = { "ds-cfg-public-key-certificate;binary" };
searchControls.setReturningAttributes(attrIDs);
final SearchResult certEntry = ctx.search(dn,
"(objectclass=ds-cfg-instance-key)", searchControls).next();
final javax.naming.directory.Attribute certAttr
= certEntry.getAttributes().get(attrIDs[0]);
/* attribute ds-cfg-public-key-certificate is a MUST in the schema */
assertNotNull(certAttr);