Group lookups failing


I have pam_ldap and nss_ldap on a test Mandrake box. Authentication is
working without issue back to an Openldap server. 

User lookups are working fine.
However group lookup fails: "getent group" returns nothing, and 'ls' lists
group numbers instead of names. 
"getent shadow" and "passwd" return expected values.

This is probably a simple problem but after a day of looking I can't see
anything. Any help would be appreciated!

My config:

group:      ldap nisplus nis

nss_base_group          ou=Group,dc=somedomain,dc=com?one

nss_ldap version: 189-2
pam_ldap version: 148-1
Openldap version:  2.0.21-1


