True enough, though I've kept them in sync before by splitting /etc/passwd et al up into machine-local and shared ranges, then rsyncing the shared set across and catting the two together under (at the time) cfengine control. (Though LDAP works, it could be considered a cure worse than the disease. NIS, well, shudder. Hesiod, perhaps?)