Samba either needs to work with pam_krb5 to map winbind usernames to kerberos principals, or it needs to re-implement pam_krb5 inside pam_winbind. Whichever we end up with, we need users to transparently gain kerberos credentials when they login, so that tools like libsmbclient can use them transparently (bug 742).
later.
This is beeing worked on in trunk
code is in SAMBA_3_0