At the moment what you say it is not possible. In the future I am going to extend the captive portal authentication methods with the GSSAPI. By using these, the captive portal is able to recognize an user who has a valid Kerberos5 ticket in his credential cache. It is necessary that also the web browser is GSSAPI aware.