I'm in the process of upgrading my MIT KDC from an old version to a more
modern version.  As part of the upgrade I'd also like to refresh my
master key and all my shared (cross-realm) keys.  I found the
documentation at [0] for updating my krbtgt, service, and master keys
(although it doesn't quite talk about how to update the stash file).
However nowhere could I find any documentation for updating a
cross-realm key.  Is there such a process?



[0] https://web.mit.edu/kerberos/krb5-1.12/doc/admin/advanced/retiring-des.html

