I feel like jumping up and down after I got FreeRadius, samba winbind, XCA w/ ECDSA certs, Active Directory, and Ubiquiti Unifi all talking together.
Next problem, any valid account in ActiveDirectory will currently authenticate. How do I limit this to the members of a specific AD group?
One terrible way I had thought of was in in the post-auth module executing a bash script that does a quick LDAP search. Could anything bad happen from this?
EDIT
Here's a guide to getting it all to work! https://gist.github.com/exabrial/368c279aad65cefd8c5f