Freeradius nested groups using ldap module to samba

I have set up lab, where freeradius is connecting to AD and checking user group membership for conditional addtributes. Nested groups work perfectly.

Now I have an idea to replace that AD with Univention, but I can’t connect freeradius to samba. Problem seems to be in TLS, and I’m stuck there.

Would someone be so kind to give me a hint on how to configure external freeradius to UCS samba with nested groups?

Thank you.