account lockout PAM module for LDAP

I'm using nss-pam-ldapd for tac_plus authorization on an Ubuntu 10.04 box and 
would like to implement an account lockout policy if there are too many failed 
login attempts.  I've looked at pam_tally, but that only works for local users 
on the tac_plus server.  My tac_plus server talks to a remote LDAP server for 
authorization.  Does anyone know of a module similar to pam_tally that will 
work with LDAP?


