I don't think that can be done.
When defining crypto ACL on the the 506, what traffic are you going to define as interesting? You can't define a crypto ACL for PIX's outside interface sourcing OSPF traffic. Also, OSPF uses multicast traffic to establish neighbor adjacency, and since the neighbor command is not available on the PIX, you't can't statically configure a neighbor to pass unicast update. IPSec will not pass multicast traffic, only GRE could.
The biggest hurdle is that PIX simply won't send traffic out the same interface it receives from, VPN or not. Thus, you can't pass traffic to the PIX and ask it to redirect that traffic out to the Concentrator.