If you need ILM or FIM to populate users in exchange you need kerberos-auth on your CAS-server.
If you have a CAS-Array and have a load-balanced solution you need kerberos-auth on your CAS-array and this is not implemented as standard.

Look at this post to get kerberos to work on your array: http://setspn.blogspot.com/2010/08/exchange-2010-enable-kerberos-on-cas.html