I'm not saying it's _hard_, it's just _different_ and would be a challenging migration for established apps as I don't know of any framework's authentication system that works like that.
Also, why would you sync pg users in ldap? pg can auth against ldap.