FreeBSD 8.2: state of Kerberos, GSS-API and (Cyrus) SASL?

Vallo Kallaste kalts at
Mon Jan 31 20:41:06 UTC 2011

On Mon, Jan 31, 2011 at 05:43:20PM +0100, Jan Henrik Sylvester
<me at> wrote:

> >cyrus-sasl2 integration with base Heimdal? With ports Heimdal? Can I
> >replace base Heimdal with one from ports, is it supported? Any
> >make.conf knobs to fiddle with? Any info appreciated.
> I am struggling with exactly the same problem. Unfortunately, I got
> no reply on this list about it:
> If you get any further, please, tell me. I am thinking about
> reposting my question to a different list: stable as that is where
> the earlier discussions happened or ports as that seems more
> appropriate.
> What I have not tried, yet, is using MIT Kerberos from ports instead
> of Heimdal, but since we use Heimdal here for everything, I am kind
> of reluctant. (Otherwise, I would have to setup some Linux
> server...)
I looked around for knobs to disable building base Heimdal and other
kerberised bits in hope that security/heimdal could be installed
into /usr. Nothing in make.conf but I found new /etc/src.conf file,
sure things have changed since 5.1 days when I left. Oh the horror
days of 5.x, but I digress.
Anyway, I think that by fiddling with src.conf knobs one can
suppress building the base Heimdal and all other kerberised things.
After one modified build and installworld the old bits lying around
should be removed and Heimdal port installed into /usr by defining
HEIMDAL_HOME. This is for start, clean base for further exploration.
On the other hand I found the following patches in the
security/heimdal commit log:
I will try that first, but this will be no-go in production because
those patches aren't probably committed to -STABLE.

More information about the freebsd-questions mailing list