The important parts were turning off PasswordAuthentication, turning on UsePAM, and turning off SSH protocol 1 connections.
I still have PrivSep turned on, too. LDAP is listed in nss and pam configuration. Thanks, -- Scott Dier <dieman@ringworld.org> KC0OBS http://www.ringworld.org/