Thanks! The CN=users prefix was what I was missing.
Two things don’t seem to work: restricting LDAP users to those in a specific group just causes them all to fail, and some longer or more complicated passwords seem to fail in WordPress even though they work in other scenarios.
I’m afraid I don’t have an answer to your question, but rather I’m trying to get this plugin to work with our Mac OS X server, and wondering how you did it. I’m not sure what to put in each of the settings, especially Account Suffix.
I’m completely new to server administration, so the LDAP configuration should all be default.