I am not sure if you can act on the samba side. Maybe you should think the other way around. You can map one attribute to another inside the LDAP server. You would use the "map attribute" directive to map "eduPersonPrincipalName" to "uid". Both logins would then authenticate against "uid".