- Add search_bind_enabled/search_bind_dn/search_bind_password to allow
using a dedicated LDAP account for user and group searches. This is
needed when regular LDAP users lack search permissions (common with
restrictive ACLs on OpenLDAP).
- Support both group_indentifier (original) and group_identifier config
keys, falling back to 'cn' if neither is set.
- Skip the gidNumber-based primary group query when the attribute is
empty, avoiding broken LDAP filters on non-posixAccount setups.