  1. I think no additional configuration is needed because the file /etc/nsswitch.conf contains the entry
    passwd: files ldap

    This will do the trick.

  2. The 1st method suggested is now deprecated
    The second solution is usually configured already, so that not a solution
    The real problem is usually in the configuration of pam
    edit or create file:
    comment out or delete line:
    # account required pam_access.so
    This removes the requirement that the user should have a local account.
    The above line is usually present in systems installed via kickstart

