Maybe you should rather use
pam_password exop
in /etc/ldap.conf, and ensure that you are using pam_ldap for
authentication,
and not nss_ldap->pam_unix which limits you to the insufficiently encrypted crypt hash.
Yeah, we figured that out yesterday, too. Thanks.
rone