Generate 12 random bytes and encode them with Heimdal base64url, producing
16-character random passwords with 96 bits of entropy.
This avoids punctuation and quoting issues while still raising generated
password entropy substantially from the old roughly 55-bit generator.
Fixes#1145