If it's plain OpenLDAP The libpam-ldapd route is the least painful because the installer prompts you interactively and auto-configures nsswitch.conf + PAM: sudo apt install libnss-ldapd libpam-ldapd When it prompts, just fill in: LDAP server URI: ldap://your-server:389 Search base: dc=example,dc=com Check passwd, group, shadow Then set the bind DN/password: sudo nano /etc/nslcd.conf binddn "cn=readonly,dc=example,dc=com" bindpw your-password sudo systemctl restart nslcd sudo reboot # /etc/nslcd.conf # nslcd configuration file. See nslcd.conf(5) # for details. # The user and group nslcd should run as. uid nslcd gid nslcd # The location at which the LDAP server(s) should be reachable. uri ldap://10.3.12.13:3189 # The search base that will be used for all queries. base dc=rhodiumlab,dc=org # The LDAP protocol version to use. #ldap_version 3 # The DN to bind with for normal lookups. binddn cn=admin,dc=rhodiumlab,dc=org bindpw "password" # The DN used for password modifications by root. #rootpwmoddn cn=admin,dc=example,dc=com # SSL options #ssl off #tls_reqcert never tls_cacertfile /etc/ssl/certs/ca-certificates.crt # The search scope. #scope sub