We're all still learning all this stuff, since much of it has never been done before, so don't take my words as authoritative.
What I'd like to see similar to this is a Keyhotee based VPN, and Keyhotee key secured remote access. Combined with decentralized storage, I think this could offer more functionality, as well as finer granularity of control than Active Directory.
There's an old project to manage OpenSSH key lookups through the PGP Web of Trust, but I think Keyhotee would be much more elegant for this sort of thing:
http://web.monkeysphere.info/Keyhotee based logins to the local machine would be great, but to be secure I think it would require using a phone or other trusted device to pass the credentials.