In your pam auth section:auth [success=1 default=ignore] pam_unix.so auth required pam_ldap.so use_first_passauth required pam_permit.soIn your ldap.conf (for the pam/nss stack):bind_policy soft