master
sig-auth: fix KAS options OWNERS
fix overlapping client CA and requestheader CA validation with proper certificate checking
add ability to authenticators for dynamic update of certs