- Add --keepold/keepallold/pruneall options to various kadmin/ktutil
   commands.  Default behavior to "prune old keys".
 - When setting keys for a service, we need to specify enctypes for it:
    - Always use kadm5_randkey_principal_3() instead of the older
      kadm5_randkey_principal().
    - Add krb5_string_to_keysalts2(), like MIT's krb5_string_to_keysalts(),
      but with a context, and simpler.
    - Add --enctypes options to various kadmin/ktutil commands.
    - Add [libdefaults] supported_enctypes param with enctype[:salttype]
      list.
    - Add [realms] realm supported_enctypes param with enctype[:salttype]
      list.
      Default to aes128-cts-hmac-sha1-96:normal.
		
	
		
			
				
	
	
	
		
			16 KiB
		
	
	
	
	
	
	
	
			
		
		
	
	
			16 KiB