The problem with arsxml, as I see it, is that the new LDAP users need to have the same permissions as the old RACF users. I tested exporting users using arsxml, and the only permissions exported are to the user itself, not the Application Group and Folder permissions. Without the Application Group and Folder permissions, adding users using arsxml does not appear to meet the requirements.