Thanks Nick.
1. I wanted to store them so i dont have to use SSO every time a user logs in; it is not crucial, so I can do with the default (or option 2 of the previous post) LDAP plugin.
2. I had seen the extension, but wasn't sure if it was 2.5 compatible (why is there no version badge on the tools section?).
3. I believe that with the above-mentioned tool, I will be able to take care of it.
One final question, what if there is no email attribute saved in AD, will users be able to login to the J site (as an email address is required)?
Thanks in advance,
Chaim