Also I just found this about the July 2006 Samba release. It indicates that ACL selection from Windows client should now work. 

                  ===============================
                   Release Notes for Samba 3.0.23a
                             Jul 21, 2006
                   ===============================
Common bugs fixed in 3.0.23a include:
  o Failure to strip the domain name from groups when 'winbind 
    use default domain = yes'
  o Failure in pam_winbind to correctly parse arguments.
  o Bad token creation of local users on member servers not 
    running winbindd.
  o Failure to add users or groups to ACLs using the Windows
    object picker.
  o Failure in file serving code when 'kernel oplocks = yes'.