It's currently sillyshell, which does not exist anymore. We override it to be /bin/bash everywhere in nss_ldap.conf and that means we can't actually set it to anything other than /bin/bash.
As of May 4th 2017:
$ ldapsearch -LLL -x -b 'ou=people,dc=wikimedia,dc=org' "(&(objectClass=person)(!(loginShell=/bin/bash)))" dn loginShell dn: uid=river,ou=people,dc=wikimedia,dc=org loginShell: /usr/bin/zsh dn: uid=shinken,ou=people,dc=wikimedia,dc=org loginShell: /bin/false $
<%- if @shell_override %> map passwd loginshell "<%= @shell_override %>" <%- elsif @realm == "labs" %> map passwd loginshell "/bin/bash" <%- end %>