Decides whether a realm's krbtgt is due for rotation from its state and the time; never while the version the last rotation kept is inside its window. Pure.
the register's krbtgtState()
the time, in epoch milliseconds
the rotation interval
{ due, dueAt, lastMs, openUntilMs, why }, with first when no
key is stored yet
Forwards to
KrbtgtRotation.decide()on the installed instance.