DOLS subscriptions may not be able to synchronize when the "compare Notes public keys against those stored in Directory" field is set in the security section of the on-line server document. When this field is set in the server document, a subscription may fail synchronization at 5 - 10%, and then generate the error, "Your public key does not match the one stored in the Address Book," and the synchronization status will go to "Idle". The Server console will read: "CN=[username]/O=[domain] failed to authenticate: Your public key does not match the one stored in the Address Book."
Workaround: Disable the "compare Notes public keys against those stored in Directory" field in the security section of the server document, restart server.