I have always tried to avoid kerb5 if I could, it might be there.
As you have been very complete, not sure how much wisdom I can add. However, I would start by adding a 'FAILED' block to the SYSTEM setting, and I don't see the registry setting anywhere.
From memory, it is the combination of registry + SYSTEM that determines where login looks for the authentification files. WINDBIND is probably looking by default where it should, but AIX might still be confused (a bit).
Also check a *.debug output to syslog files, just incase something useful shows up there.
And when you get this working, please let me know

as I have never taken the time to get samba to work - although it would be nice now that my kids all have comps in their rooms.
And then I guess the last part - is samba file/print sharing working or not?