current password expiration methods

I would like to get opinions on current methods of handling password expiration and history within LDAP. When I last checked, I remember something about ppolicy, I believe it had just entered CVS or something... Is this an acceptable method of achieving the above goals? I assume this question should be pretty straight forward, but if more info is needed, Let me know. Thanks.

OpenLDAP 2.2.7 (Debian Package)

Thomas Simmons