Kerberos is really complicated. I am currently setting up LDAP, and have it storing SSH keys. Which is a far simpler setup.
Also make sure to deploy the ssh keys somewhere the users can't write for extra security. Don't allow them to control their own authorized_keys files! :-)