if you really do actually mean ldap authentication then you'd want to look at a replacement gina, like pgina (google for it) if you actually are expecting full domain membership, then that's not what ldap is, you'd need to run samba to replicate an active directory domain.
|