So, we're currently leaning towards #5, but would be interested to know if there is a better way of implementing this using OpenLDAP (since other people have presumably done this kind of thing in the past).
--Quanah
-- Quanah Gibson-Mount Principal Software Developer ITSS/Shared Services Stanford University GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html