well i did it...
i wrote a ldap-client that doesn't depend on openldap... still need to add kerberos support and regress my filters, but it should be enouh to add to my nameserver and finally end some of the worst outstanding problems.
it will be glorious