Locking of principals after failed logins


we are now able to shut down AFS kaserver and replace it with the heimdal
kdc. One good feature the kaserver has, is to lock principals after a
number of failed login tries. This feature seems to be missing in the kdc
or am I just looking at the wrong place?

When examining principals with kadmin get there is a field "Failed login
count". What can I do if there is a very high number behind it?

Thanks in advance

