OK, so it's the ADsDSOObject provider that's the limiting factor here. It's apparently AD-only, and will not work properly for non-AD LDAP. That's why it returns only the ADsPath field, and tosses any other fields that are returned.
It appears, too, that the Sun-LDAP support is then limited to the Server-side Configurable LDAP setting, and not for direct query from an application's script.
Someone please correct me if you have better information.