Hi. Long time since last post in this thread but i have been having problems with this also so i thought i post a solution.
I finally managed to logon with AD account. All explained in this post. http://www.theitblog.se/2014/11/19/ldap-hp-sim/
This is without TLS though but maby its possible to add encryption if you get it to work like this first.
briefly i did this.
1. Install krb5 winbind
2. edit krb, samba, nsswitch configuration files
3. add computer to domain.
4. set mxpamauthrealm to winbind
5. add AD group to HP-sim.
6. reboot and login with AD account.