I have not touched that in a while so I may be off, but I think this

<LocationMatch /trac/[^/]+/login>

    AuthName "Trac"
    AuthType Basic
    AuthBasicProvider file ldap

    AuthUserFile /path/to/trac/.htpasswd
    AuthLDAPURL  "ldap://IP.AD.DR/ou=People,dc=YOUR,dc=DC";
    AuthzLDAPAuthoritative Off

should do the trick and also let you have extra users in .htpasswd (e.g.
if you have outside beta-testers you don't want to give an ldap acct to)

