Restricting login to certain hosts


I manage linux user accounts in an ldap database and use openldap and pam for
login authentification. Now I would like to
restrict the access of these users to only certain host machines. I know that I
can add a "host: " directive(s) to an account-object
in ldap but how can I make pam have these entries checked and possibly deny
access if a user logs in to a host for which no
"host " directive exists in his account?

