Subject: SVN Commit

When we check for password reuse, only compare keys with the most
recent kvno against history entries, or else we will always fail with

This bug primarily affects rollover of cross-realm TGT principals,
which typically use password-derived keys and may have an associated
password policy such as "default".

Bug report and candidate fix (taken with a slight modification) by
Nicolas Williams.
Commit By: ghudson
Revision: 25801
Changed Files:
U trunk/src/lib/kadm5/srv/svr_principal.c