When you say via LDAP, do you mean using the LDAP plugin in Directory Utility or are you using the Active Directory plugin? You should be using the AD plugin. DNS is critical to success. Your AD server must be configured with the proper SRV records and your Mac should be using the DNS from the AD box as primary DNS. Next to DNS is time. The Mac and the AD box must be within a narrow delta of time variance.
Try this. Open System Preferences. Select Users & Groups. Click on Login Options. Unlock the pref panel. Press the Join button next to Network Account Server. Press the Open Directory Utility button. Unlock that tool. Select Active Directory and try binding from there. Once again, DNS and time must be in line.
Reid
Apple Consultants Network
"El Capitan Server – Foundation Services"
"El Capitan Server – Control & Collaboration"
"El Capitan Server – Advanced Services"