Could it be possible to use winbind kerberos ticket to authenticate to openldap when using it as idmap backend ? this way i would not have to record a ldap admin password in secret.tdb. Thanks