4.23.2 Using Kerberos database

That's a section of <http://www.pdc.kth.se/heimdal/heimdal.html> that  
isn't filled out.

I would assume that it's intended to describe how to put the PKI cert  
name <--> Kerberos Principal mapping into the database itself instead  
of in the cert's.  That's allowed by the RFC, but perhaps not often  
done by people who *can* put them in the cert's.

Should I conclude that the code to support that mode is likely to  
have bugs, or more politely, to be incomplete?
