alright, it looks like /etc/ldap_fluff.yml isn't getting generated. if i create it by hand, i can then login
let's be sure that the official SAM docs are correct