Sorry for the zombie thread, but this is the first search result for "samba domain" so I thought I'd clarify a few things.
I'm working on setting up a similar situation, and from what I've read so far, you can have the filer join the domain like any other domain, provided you have an account mapped to the "Domain Admins" group in the Samba domain. How this works with the various back-ends (i.e., LDAP), however, is something I'm still working out.
Also, the requirement for plaintext passwords when using LDAP is only if you're using the "native" LDAP support on the filer, (option 4 in cifs setup). But since you'll be using AD authentication, the full gamut of authentication mechanisms should be supported.