pam_groupdn: multi-valued?

Hi all, 

The RH-PAM list and google got me nowhere, so here I am. I'm just
wondering if my efforts to get pam_groupdn (in /etc/ldap.conf on RH9) to
enforce membership of any of 3 groups are failing because of syntax
weirdness or because it's just not supported. Does anyone happen to have
this kind of thing working? I really don't want to have to add all of
the users permitted to log on to a machine to a single group. 

PS  - is there a manpage for /etc/ldap.conf? The default one is for
/etc/openldap/ldap.conf, which has little or nothing to do with nss.