If it's plain OpenLDAP The libpam-ldapd route is the least painful because the installer prompts you interactively and auto-configures nsswitch.conf + PAM: sudo apt install libnss-ldapd libpam-ldapd When it prompts, just fill in: LDAP server URI: ldap://your-server:389 Search base: dc=example,dc=com Check passwd, group, shadow Then set the bind DN/password: sudo nano /etc/nslcd.conf binddn "cn=readonly,dc=example,dc=com" bindpw your-password sudo systemctl restart nslcd sudo reboot