With users in ldap both su (to root) and sudo doesn't work when nscd is not running. Maybe unrelated, but here even with nscd running, su (from ldap user to ldap user) isn't working:
f...@linux % su bar Password: initgroups: Operation not permitted -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org