So, pam_krb5_migrate targets the Heimdal Kerberos distribution, which has admin functions incompatible with MIT Kerberos. Guess which distribution ships with Red Shat?
So, the other alternative is
this, which doesn't seem dodgy at ALL --- No, just pass a shell script the user's password in an environment variable, and poke the KDC. Twitch.