Since we store kerberos credentials in sssd-secrets, it would be nice to also have a per UID quota so that a single user cannot DoS other users and prevent them from authenticating to their realm account.

