-implement rfc2898 pkcs5 pbkdf2 key derivation -add configuration file support -add munged 'k' cmdline opt to kill daemon -save/restore replay state at munged shutdown/startup -restrict decode to hostname/hostrange/regex or ip-addr/netmask -add config opt to specify n/w interface for determining ip -add pam support -add realm (multi-key) support -periodically stat keyfile and look for changed inode/mtime -change remunge to exit on persistent errors -change remunge to stop and output results on sigint