in reply to Authenticate to NT domain or AD?

You may also want to check out auth_ldap as it has some (all?) of what you want already done.

HTH, --traveler