So the problem I have with this is that it collides with using Puppet to manage your users--Puppet will have to know about the users' Unix passwords.
It should be fairly straightforward to write a script that tests for SSH keypairs with an empty passphrase, simply try to authenticate an SSH agent by loading the user's key.