openldap auth over SPA (aka NTLM) or bind subquery

Hi all
I have two question
1. Is it possible to enable in openldap NTLM auth (as known as SPA option in Oulook)? Is method=137 (which sends oulook) supported ? Maybe some additional patches are avaliable?
2. Is there any way to rewrite incoming DN for bind operation to make some subquery to the same ldap database (without sasl-regexp, it dont work with outlook, look at the first question)? My users need to authentificate using for login their email address, so I need to make some subquery to find their real DN, and compare it with password submited with email address.


Best regards,
Maxim Cherniavsky
mailto: maxim (at) comstar.ru