Miscellaneous questions regarding krb5.conf?

Good day!

I have a few questions:

1. Where is that [password_quality] section located in the manual as discussed in this link: http://www.openinput.com/auth-howto/ar01s06.html, where I can set the minimum password length as well as the allowable characters and possible the invalid password possibly taken from dictionary?

2. "privilages" command in kadmin doesn't work
3. perhaps the krb5.conf manual should indicate which sections/bindings is for a client and which is for a server. When I kinit from a machine with a lifetime of "10 hours" (kinit -l "10 hours" myusername@OUR.REALM) I got a ticket with a ten hours lifetime even if the "ticket_lifetime" in the [libdefaults] section of the kdc's krb5.conf is set to only 8 hours as well as in the clients krb5.conf.

4. How can I enforce the attributes of the tickets obtained from the kdc by a client (eg. I don't want any ticket to be forwardable?) I noticed that kinit uses! the [libdefaults] section to look for possible ticket attributes even though none of those attributes exists in the kdc's krb5.conf (libdefaults) section.

That's all for now...

