Sorry, the request for LDAP auth not NTLM. So that link was EXACTLY how to do ldap auth against AD. The only thing is you don't change the system PAM file, you create a new one. Then you point the radius to it, using PAM and that service file, I think it is the text string option that specifies the pam service.
How you use or transport the request via radius is a separate issue. You are using PAM to link together the AD to the radius server to your clients.
|