Is there any way to use one of LDAP's DN-based groups for linux groups instead of using the uid-based posixGroup objectclass?
More broadly, is there any way I can avoid having one set of groups for supporting linux accounts and a parallel set of groups that's used by everything else?