I'm using OpenLDAP's memberof overlay which automatically maintains reverse group memberships. Unfortunately, that doesn't work with the plugin (version 1.2c) because memberOf is an operational attribute and thus must be requested explicitly. A simple patch is to replace line 1087 (function getUserInfo()) of LdapAuthentication.php with the following one:
$entry = @ldap_read( $this->ldapconn, $this->userdn, "objectclass=*", array('*', 'memberOf') );
Could you integrate this patch to the trunk if it looks reasonable enough?