BTW, another one idea: We can set a password manager for a principal folder, not for a individual principal, so all principals in the folder will be use the only one password manager.

I like that even better. +1

Ok, so I'll redo the implementation and get rid of the generation.

Oops, we can't get rid of the generation since we need to encode the password anyway... :-/

