krb5_ldap_lockout_check_policy
retval = krb5_ldap_lockout_check_policy(kcontext, client, kdc_time);
krb5_ldap_lockout_check_policy(krb5_context context,