We use LDAP and it does everything.