Ran into this issue on AIX, and the AIX guy kept coming up with this doc. (Hey Duane!) Just to call it out, but this one line, solved our issue:
userattrmappath Path to user attribute map
I was watching in Dstrace +LDAP and seeing all these AD style attributes being requested, and I tried to map them one by one. I kept noting that somehow we were thinking we were pointing at AD, not LDAP/eDir.
Reading your article pointed me right at that key file, and lo and behold there it was, wrong map file. Awesome, now we can fix it.
Now what is shadowLastChanged (mandatory) meant to store? Hmm... I can make it have whatever we need via IDM or map it to whatever we need it to be. But that is an 'easy' one to resolve I think.