The LDAP sync can be a pain with large LDAP directories. Can you elaborate on your web script-based approach a little further? Are you proposing an approach whereby some other system (LDAP, or something else that was watching LDAP for changes) would process changes by invoking a web script? Or something different?
Could you tell us how, ideally speaking, you would like to integratie with LDAP? On connection time, nighly, etc? There are other more suitable options available then webscripts imho.