using ldap as heimdal backend


This is probably a basic question but well, I haven't
got any satisfactory information on the net, so I post
it anyway here.

I read somewhere in the net that using ldap as the
backend of heimdal might degrade the security feature
of kerberos. Is this right ? If yes, then in which
situation will we prefer to use ldap backend instead
of the local dbase ?

Using ldap as the heimdal's backend, how would the
search be conducted through ldap ? With simple bind ?
SASL mechanism ? 

Thx in advance :-)

