check_kerberos_principal_expiry: new plugin
This MR adds a check_kerbeos_principal_expiry
plugin to check the expiry of a Kerberos principal synchronised to LDAP.
This should allow automated testing and notification of pending expiry for robot Kerberos principals (see computing/helpdesk#5225).