/etc/passwd or /etc/shadow, to a Kerberos password database can be tedious, as there is no automated mechanism to perform this task. Refer to Question 2.23 in the online Kerberos FAQ:
[18] A system where both the client and the server share a common key that is used to encrypt and decrypt network communication.