I'm not asking for Samba to acquire Kerberos tickets, nor do I 
require that the client get tickets.  All I want to do is use 
Kerberos to *authenticate* the clients.

In theory, shouldn't I be able to have the client send the password 
to Samba, then have Samba use PAM to see if that password is 
legitimate?  What PAM does with it (i.e. pass it off to Kerberos) 
should be transparent to Samba and the the client.  

(though, I'm likely to need to have the clients configured to use 
cleartext passwords, which is not great, and really defeats the point 
of Kerberos ! :(

