* Maybe use krb5_aname_to_localname to do principal/login mapping?
* Ensure we're compliant with the PAM specs wrt return values.
* Add support for account expiration.
* Use libtool to build the modules.
