Hello, Does IPA need to include the following feature: - auto-renew kerberos machine principal and service principals We are wondering if that is something that you are looking for. Of course, we would enable auto-renew of a cert but do you see much value in auto-renew of the kerberos principals? Thanks, Karl