Firewall: IPTables if you're running a firewall on the box. However, if you're running a firewall edge of network, then I'd go with a dedicated solution like Shoreline, Smoothwall or ClarkConnect.
LDAP: OpenLDAP. By itself, OpenLDAP is not difficult. However, as you add layers to it like TLS and Kerberos, etc. then the configuration becomes obtuse.
Web server: Nginx (the current king), but Apache is still a strong choice. Nginx works great with the newer frameworks where you're running it as a proxy for your application server plus as a high performance static file server. Apache is still solid if you're developing in PHP.
You should firstly find out what they mean by "untested sources", as this could mean building code from source/tarballs and not using their 1-click installer for software (where a lot of the software will likely be open source in any case).