The passthru subsystem is for use with a Windows Domain server (or indeed a samba server). So you need one of those if you want to use the passthru subsystem. The idea is that the password doesn't have to be duplicated anywhere else and is instead validated directly against the domain server.
However, if you use the alfrescoNtlm subsystem instead, alfresco will function as a fully-functional CIFS server that can authenticate its own internal users. Because of the negotiatian mechanism involved in CIFS authentication, it would not be possible for CIFS to authenticate the LDAP users, but they could still log in to the web clients.