Pam and ppolicy

I'm trying to setup a box to use openldap with the password policy overlay. Redhat's authconfig successfully creates a pam config that uses ldap. It works just fine except that the password policy warnings aren't picked up by pam. I can see in my ldap server logs that the ldap server tries to enforce a password change, but this isn't displayed to the user. The result, of course, is that the password expires silently, leaving the user locked out with no warning and no way to change the password.

Please excuse this if the solution is obvious. I've found some howto's that did not work as expected. If someone could direct me to an accurate howto, I'd greatly appreciate it.
