audit account-keyring
Look at all the keys in account-keyring, for each key:
- if the account is locked in LDAP, remove the key
- if the key is expired, consider locking it in LDAP
Consider automating this, or at least make it so automation wouldn't be harder, see #29671 (moved).