The WLC cannot authenticate users via LDAP, only radius. If you setup your server to talk radius that is taken care of. Which vlan to terminate the clients on is just a matter of getting that vlan into the wlc (if not already there), create a virtual interface in wlc for that vlan and connect the wlan/ssid to that virtual interface.
No caveats as far as I can see.
/Kvistofta