Your best bet is to review the documentation for the FTP program. That kind of support usually has to be compiled into the FTP program specifically, unless the author decided to add it by default. Either way, you'd have to check the docs.
IIRC, ProFTP and Pure-FTP both have the ability to support this. The general theory is that you have a non-privileged AD user (that can read from AD, but not write) scan through the AD to see if the user (that is requesting FTP access) exists in the AD. Then the FTP program needs to compare the supplied password (hashed correctly) with the hash in the AD. The only problem is ensuring that the FTP program is using the same authentication scheme as the FTP (Kerberos, I guess?).
While AD is LDAP-like, it is not LDAP.
Last edited by 3rods; 03-26-2008 at 08:58 AM.