| Port details |
- freeipa-server FreeIPA server
- 4.13.1 net
=0 Package not present on quarterly.This port was created during this quarter. It will be in the next quarterly branch but not the current one. - Maintainer: joneum@FreeBSD.org
 - Port Added: 2026-08-18 20:42:06
- Last Update: 2026-08-18 20:41:19
- Commit Hash: 35e4879
- License: GPLv3+
- WWW:
- https://www.freeipa.org/
- Description:
- FreeIPA server provides integrated identity management,
authentication, authorization, and policy services based on
LDAP, Kerberos, DNS, and PKI technologies.
¦ ¦ ¦ ¦ 
- Manual pages:
-
- pkg-plist: as obtained via:
make generate-plist - USE_RC_SUBR (Service Scripts)
- ipa-custodia
- freeipa-server
- Dependency lines:
-
- freeipa-server>0:net/freeipa-server
- Conflicts:
- CONFLICTS_INSTALL:
- To install the port:
- cd /usr/ports/net/freeipa-server/ && make install clean
- To add the package, run one of these commands:
- pkg install net/freeipa-server
- pkg install freeipa-server
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.- PKGNAME: freeipa-server
- Flavors: there is no flavor information for this port.
- distinfo:
- TIMESTAMP = 1782325059
SHA256 (freeipa-4.13.1.tar.gz) = 5353127d7c56ca72bc2d458376d457f8b0cc451cdbd31dc7939a88058e91527c
SIZE (freeipa-4.13.1.tar.gz) = 41552419
No package information for this port in our database- Sometimes this happens. Not all ports have packages. This is doubly so for new ports, like this one.
- Dependencies
- NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
- Build dependencies:
-
- getopt : misc/getopt
- dirsrv.pc : net/389-ds-base
- sss_idmap.pc : security/sssd2
- py312-setuptools>0 : devel/py-setuptools@py312
- py312-lesscpy>0 : www/py-lesscpy@py312
- py312-pip>0 : devel/py-pip@py312
- py312-rjsmin>0 : archivers/py-rjsmin@py312
- bash : shells/bash
- samba416>=0 : net/samba416
- gettext-runtime>=0.26 : devel/gettext-runtime
- gettext-tools>=0.26 : devel/gettext-tools
- gmake>=4.4.1 : devel/gmake
- libkrb5support.so : security/krb5
- node : www/node24
- pkgconf>=1.3.0_1 : devel/pkgconf
- python3.12 : lang/python312
- autoconf>=2.73 : devel/autoconf
- automake>=1.18.1 : devel/automake
- libtoolize : devel/libtool
- Test dependencies:
-
- python3.12 : lang/python312
- Runtime dependencies:
-
- mod_auth_gssapi.so : www/freeipa-auth-gssapi
- mod_deflate.so : www/apache24
- mod_expires.so : www/apache24
- mod_lookup_identity.so : www/mod_lookup_identity
- mod_proxy.so : www/apache24
- mod_proxy_ajp.so : www/apache24
- mod_proxy_http.so : www/apache24
- mod_rewrite.so : www/apache24
- mod_session.so : www/apache24
- mod_session_cookie.so : www/apache24
- mod_ssl.so : www/apache24
- mod_wsgi.so : www/mod_wsgi@py312
- certmonger : security/certmonger
- gssproxy : security/gssproxy
- httpd : www/apache24
- oddjobd : sysutils/oddjob
- py312-dbus>0 : devel/py-dbus@py312
- py312-gssapi>0 : security/py-gssapi@py312
- py312-ifaddr>0 : net/py-ifaddr@py312
- py312-jwcrypto>0 : security/py-jwcrypto@py312
- py312-kdcproxy>0 : security/py-kdcproxy@py312
- py312-lib389>=0 : net/py-lib389@py312
- py312-netaddr>0 : net/py-netaddr@py312
- py312-python-augeas>0 : textproc/py-python-augeas@py312
- py312-python-dateutil>0 : devel/py-python-dateutil@py312
- py312-qrcode>0 : textproc/py-qrcode@py312
- py312-sqlite3>0 : databases/py-sqlite3@py312
- py312-urllib3>0 : net/py-urllib3@py312
- 389-ds-base>=0 : net/389-ds-base
- dogtag-pki>0 : security/dogtag-pki
- samba416>=0 : net/samba416
- slapi-nis>=0.70.0 : net/slapi-nis
- libkrb5support.so : security/krb5
- python3.12 : lang/python312
- Library dependencies:
-
- libcurl.so : ftp/curl
- libini_config.so : devel/ding-libs
- libintl.so : devel/gettext-runtime
- libjansson.so : devel/jansson
- libkrad.so : security/krb5
- libnspr4.so : devel/nspr
- libpopt.so : devel/popt
- libpwquality.so : security/libpwquality
- libsasl2.so : security/cyrus-sasl2
- libsss_nss_idmap.so : security/sssd2
- libtalloc.so : devel/talloc
- libtevent.so : devel/tevent
- libunistring.so : devel/libunistring
- libuuid.so : misc/libuuid
- libxmlrpc.so : net/xmlrpc-c
- libintl.so : devel/gettext-runtime
- libldap.so.2 : net/openldap26-client
- There are no ports dependent upon this port
Configuration Options:
- ===> The following configuration options are available for freeipa-server-4.13.1:
DOCS=on: Build and/or install documentation
===> Use 'make config' to modify these settings
- Options name:
- net_freeipa-server
- USES:
- autoreconf gettext-runtime gettext-tools gmake gssapi:mit iconv ldap libtool localbase:ldflags nodejs:build pkgconfig python shebangfix ssl
- pkg-message:
- For install:
- ======================================================================
ATTENTION - REQUIRED before you run ipa-server-install
======================================================================
>>> Read /usr/local/share/doc/freeipa-server/README.md first,
>>> section "Prerequisites (read this first)".
FreeIPA on FreeBSD uses the MIT Kerberos from ports (security/krb5).
The SASL/GSSAPI plugin that the final "client enrolment" step of
ipa-server-install relies on MUST use that SAME Kerberos - otherwise the
install runs all the way through and then fails at the very end with:
Insufficient access: SASL(-1): generic failure: GSSAPI Error:
... (SPNEGO cannot find mechanisms to negotiate)
or
... Cannot find KDC for realm "EXAMPLE.COM"
By default security/cyrus-sasl2-gssapi is built with GSSAPI_BASE, which
links the BASE-system Kerberos (/usr/lib/libgssapi_krb5) and reads
/etc/krb5.conf - the wrong Kerberos for FreeIPA. You MUST rebuild it with
the GSSAPI_MIT option so it links the ports Kerberos
(/usr/local/lib/libgssapi_krb5) and reads /usr/local/etc/krb5.conf:
* via make.conf (ports / poudriere):
security_cyrus-sasl2-gssapi_SET=GSSAPI_MIT
security_cyrus-sasl2-gssapi_UNSET=GSSAPI_BASE
security_py-gssapi_SET=GSSAPI_MIT
security_py-gssapi_UNSET=GSSAPI_BASE
* or interactively, then rebuild + reinstall the plugin:
make -C /usr/ports/security/cyrus-sasl2-gssapi config
# select GSSAPI_MIT, deselect GSSAPI_BASE
Verify the plugin now links the ports Kerberos:
ldd /usr/local/lib/sasl2/libgssapiv2.so | grep libgssapi_krb5
# MUST show /usr/local/lib/libgssapi_krb5.so
# NOT /usr/lib/libgssapi_krb5.so.*
The Python bindings security/py-gssapi need the same GSSAPI_MIT choice;
ipalib uses them for the kinit during self-enrolment, and with the base
Kerberos the install fails at the very end with "Cannot find KDC".
Note: this is a system-wide choice. All SASL/GSSAPI consumers (SSSD,
OpenLDAP, Postfix, ...) will then use the ports MIT Kerberos - which is
the correct, consistent setup on a host dedicated to FreeIPA.
Full details and the rest of the prerequisites (FQDN, /etc/hosts,
D-Bus/dbus_enable, cloud-init manage_etc_hosts, reboot persistence):
/usr/local/share/doc/freeipa-server/README.md
======================================================================
- Master Sites:
|