How do we like our base kerberos? Will it flee soon?

Joerg Pulz Joerg.Pulz at
Thu Nov 11 15:35:07 UTC 2010

Hash: SHA1

On Wed, 10 Nov 2010, Leon Meßner wrote:

> Hi,
> I'm looking for workarounds for this crappy situation which currently
> prevents FreeBSD8 from working together with libgssapi (see kern/147454)
> and multiple threads on -questions.
> What i tried:
> - Use old RELENG_8 and RELENG_8_1 sources where Benjamin's patch still
>  applied. (Can't build world then).
> - Modify /usr/bin/krb5-config to include -lgssapi_spnego -lgssapi_krb5
>  at the right place (works on some machines).
> What i didn't try:
> - Use the port.
> How are you handling this situation. Does anyone know a cvs tag= and
> date= combination which lets you build world with Benjamin's patch
> (tried RELENG_8 and _8_1 from 24.6 and 19.7 and now)? Actually a
> complete base kerberos would be much appreciated.


please take a look at ports/152030 and the patches i mentioned in the PR.

With applied ports/152030 and the world patch applied, you should be able 
to build a world fully against the security/heimdal port by simply 
specifying WITH_KERBEROS_PORT=1 in /etc/src.conf and HEIMDAL_HOME=<prefix> 
(normally /usr/local) in /etc/make.conf.
You should specify WITHOUT_KERBEROS=1 in /etc/src.conf to avoid mess and 
confusion with two different heimdal version installed.

Don't forget to install the security/heimdal port first.

Comments are welcome.

I will send out a CFT/RFC as soon as the PR is committed.

Kind regards

- -- 
The beginning is the most important part of the work.
Version: GnuPG v2.0.16 (FreeBSD)


More information about the freebsd-questions mailing list