In the search for the integration of APEX with SSO and the OID, I became somewhat disappointed by the APEX_LDAP package.
Where it clearly states "p_group_base - The base from which the search should be started." it actually does not do a search, starting from (which would be the -s sub option in the command line ldapsearch), but expects the entry to be in that branch level.
It resembles the "-s base" option of the ldapsearch command line tool.
The scope of "sub" is default, by the way.
Took me about half a day of searching to realize the command line and the APEX package behave completely different. Renders APEX_LDAP quite useless for my environment, where user entries are NOT found IN the 'cn=Users, dc=base_ldap_domain' branch, but usually one level deeper. Now I'll have to write my own LDAP packages - which I will post when I'm satified with them.