You can switch to use SSSD instead of winbind. SSSD is capable to handle transparent kerberos ticket handling for a user logged into machine and even renew it on user's behalf.
Read chapter 11.2 of RHEL deployment guide for details: https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Deployment_Guide/SSSD-Introduction.html, specifically 11.2.13 which deals with AD domains.
You may also check AD integration presentation for SSSD: http://www.freeipa.org/images/d/dd/Freeipa30_sssd-ad-provider.pdf