You use kinit before joining the AD to test AD auth. That is, you want to be sure your "linux" side is configured properly to get a kerberos ticket in the first place. If you're able to get one, you should be to join the domain.
Ranbir, Yeah it's been working ever since but there are some errors in the logs even though users auth silently and it all just works. Once I am back from holidays I had planned to read up on winbind and samba as it relates to AD...
Thanks! jlc