I'm still working on this... I was reading this post in the archives:
http://www.mail-archive.com/freeipa-users@redhat.com/msg02049.html Dmitri's
statement "There might be some MIT documentation about how to join a Windows
machine to MIT KDC. If this can be done I am sure the same can be done with
IPA." should be true, but for the windows system to use authentication I
have to be able to set the host password in Kerberos. There doesn't seem to
be a way to do that in the FreeIPA interface. I would normally do that in
kadmin if working directly in kerberos, but that's not possible either.

*IS* there a way to set the host password so that machines can provide user
authentication for a windows client?
