Unfortunately, the real hard one is finding an implementation that integrates with JAAS; I have found most of my application servers and other components want JAAS, and I have yet to see any Kerberos-based AD integration suite that plays nicely with JAAS.