Secure WLAN with Active Directory Auth


we're going to setup a WLAN for our association.
Since we're interesent in a secure solution we tought about
securing the WLAN with IPSEC or PPTP using a debian box.
What we need is a solution to do the user authentication for
the VPN using an existing active directory.
I searched the internet for a solution but it seems
that if we use IPSEC we need to use either a preshared secret
or X.509 certs. For PPTP I read that some people using a
setup incorporating a RADIUS server. This looks very complicated
to me and not well documented.
Can anybody tell me if there's a linux based solution for
our problem?

