LDAP AD auth on woody

I have woody hosts getting account information correctly from Active
Directory, but authentication isn't working. I can do things like:

# getent passwd Administrator

...but auth doesn't work at all.

I'm not using SSL, and a domain account to bind to the directory. I
could really use two things:

1) an example working ldap.conf file to auth against AD (my
   libnss-ldap.conf seems to be ok)
2) any info on mods to the pam and nss ldap packages, in case they
   aren't built with the needed args (--enable-schema-mapping
   --enable-rfc2307bis perhaps)

Nate Campi 

