I think there should be a debian package/packages solving this problem automagically for those who do not want to go through all the reading themselves. It should contain something like this: openldap, samba, kerberos, nsswitch, pam-ldap with all the needed configuration and simple wizards, allowing to choose options.