We have an Active Directory with a cross realm trust to a MIT Kerberos realm. All normal users are mapped to an equivalent principal in the Kerberos realm. Thus we have a common single autentication system for Windows an Unix(TM)-like sytems (Linux and Tru64). Problem is, that samba seems not to be able to autenticate users. I could easily add the machine to the AD via net ads join, but smbclient -L samba_machine -k always gives NT_STATUS_LOGON_FAILURE.
This should work if you have a ticket for a user in the MIT realm and try to connect to the Samba joined to the AD domain. Can you retest against 3.0.11 and reopen if the bug still exists.
sorry for the same, cleaning up the database to prevent unecessary reopens of bugs.