Mmkay, nevermind.. I was able to figure out how to get into single user mode after all. It must ignore whatever PAM stuff you have set up and just use /etc/passwd and shadow. Good thing I didn't delete them after all.
I was surprised to find out that I couldn't even get in using SSH. I have it set to require only a valid private key from inside the LAN.
Maybe I should set LDAP to be only "sufficient" instead of "required", in case I hose it up at some later point. It's still pretty confusing to me, so I see that as rather likely.