I guess e338789d is supposed to fix this, and it's present in 2.4.40, but still I'm affected on that version:
olcUniqueURI: ldap:///o=niifi,o=niif,c=hu?gidNumber?sub?objectClass=posixGroup
rejects setting the gidNumber of a posixAccount to that of an existing posixGroup.
The usual workaround of using more specific base DNs doesn't work well for me, because there are multiple branches containing groups. Specifying multiple URIs on the above light might work (man slapd-unique doesn't tell precisely), but requires extra maintenance.