| Port details |
- freeipa-server FreeIPA server
- 4.13.2_1 net
=0 Package not present on quarterly.This port was created during this quarter. It will be in the next quarterly branch but not the current one. - Maintainer: joneum@FreeBSD.org
 - Port Added: 2026-08-18 20:42:06
- Last Update: 2026-08-25 11:19:54
- Commit Hash: 5aacc86
- License: GPLv3+
- WWW:
- https://www.freeipa.org/
- Description:
- FreeIPA server provides integrated identity management,
authentication, authorization, and policy services based on
LDAP, Kerberos, DNS, and PKI technologies.
¦ ¦ ¦ ¦ 
- Manual pages:
-
- pkg-plist: as obtained via:
make generate-plist - USE_RC_SUBR (Service Scripts)
- ipa-custodia
- freeipa-server
- Dependency lines:
-
- freeipa-server>0:net/freeipa-server
- Conflicts:
- CONFLICTS_INSTALL:
- To install the port:
- cd /usr/ports/net/freeipa-server/ && make install clean
- To add the package, run one of these commands:
- pkg install net/freeipa-server
- pkg install freeipa-server
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.- PKGNAME: freeipa-server
- Flavors: there is no flavor information for this port.
- distinfo:
- TIMESTAMP = 1787129871
SHA256 (freeipa-4.13.2.tar.gz) = 56d593de47bdd008d5df7ce219ba468e115a207eed1a32b0799e270ec0ece2aa
SIZE (freeipa-4.13.2.tar.gz) = 42032746
Packages (timestamps in pop-ups are UTC):
- Dependencies
- NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
- Build dependencies:
-
- getopt : misc/getopt
- dirsrv.pc : net/389-ds-base
- sss_idmap.pc : security/sssd2
- py312-setuptools>0 : devel/py-setuptools@py312
- py312-lesscpy>0 : www/py-lesscpy@py312
- py312-pip>0 : devel/py-pip@py312
- py312-rjsmin>0 : archivers/py-rjsmin@py312
- bash : shells/bash
- gettext-runtime>=0.26 : devel/gettext-runtime
- gettext-tools>=0.26 : devel/gettext-tools
- gmake>=4.4.1 : devel/gmake
- libkrb5support.so : security/krb5
- node : www/node24
- pkgconf>=1.3.0_1 : devel/pkgconf
- python3.12 : lang/python312
- smbd : net/samba416
- autoconf>=2.73 : devel/autoconf
- automake>=1.18.1 : devel/automake
- libtoolize : devel/libtool
- Test dependencies:
-
- python3.12 : lang/python312
- Runtime dependencies:
-
- chronyc : net/chrony
- mod_auth_gssapi.so : www/freeipa-auth-gssapi
- mod_deflate.so : www/apache24
- mod_expires.so : www/apache24
- mod_lookup_identity.so : www/mod_lookup_identity
- mod_proxy.so : www/apache24
- mod_proxy_ajp.so : www/apache24
- mod_proxy_http.so : www/apache24
- mod_rewrite.so : www/apache24
- mod_session.so : www/apache24
- mod_session_cookie.so : www/apache24
- mod_ssl.so : www/apache24
- mod_wsgi.so : www/mod_wsgi@py312
- certmonger : security/certmonger
- gssproxy : security/gssproxy
- httpd : www/apache24
- oddjobd : sysutils/oddjob
- py312-dbus>0 : devel/py-dbus@py312
- py312-gssapi>0 : security/py-gssapi@py312
- py312-ifaddr>0 : net/py-ifaddr@py312
- py312-jwcrypto>0 : security/py-jwcrypto@py312
- py312-kdcproxy>0 : security/py-kdcproxy@py312
- py312-lib389>=0 : net/py-lib389@py312
- py312-netaddr>0 : net/py-netaddr@py312
- py312-python-augeas>0 : textproc/py-python-augeas@py312
- py312-python-dateutil>0 : devel/py-python-dateutil@py312
- py312-qrcode>0 : textproc/py-qrcode@py312
- py312-sqlite3>0 : databases/py-sqlite3@py312
- py312-urllib3>0 : net/py-urllib3@py312
- 389-ds-base>=0 : net/389-ds-base
- dogtag-pki>0 : security/dogtag-pki
- slapi-nis>=0.70.0 : net/slapi-nis
- sssd2>=2.13.1_2 : security/sssd2
- libkrb5support.so : security/krb5
- python3.12 : lang/python312
- smbd : net/samba416
- Library dependencies:
-
- libcurl.so : ftp/curl
- libini_config.so : devel/ding-libs
- libintl.so : devel/gettext-runtime
- libjansson.so : devel/jansson
- libkrad.so : security/krb5
- libnspr4.so : devel/nspr
- libpopt.so : devel/popt
- libpwquality.so : security/libpwquality
- libsasl2.so : security/cyrus-sasl2
- libsss_nss_idmap.so : security/sssd2
- libtalloc.so : devel/talloc
- libtevent.so : devel/tevent
- libunistring.so : devel/libunistring
- libuuid.so : misc/libuuid
- libxmlrpc.so : net/xmlrpc-c
- libintl.so : devel/gettext-runtime
- libldap.so.2 : net/openldap26-client
- There are no ports dependent upon this port
Configuration Options:
- ===> The following configuration options are available for freeipa-server-4.13.2_1:
DOCS=on: Build and/or install documentation
===> Use 'make config' to modify these settings
- Options name:
- net_freeipa-server
- USES:
- autoreconf gettext-runtime gettext-tools gmake gssapi:mit iconv ldap libtool localbase:ldflags nodejs:build pkgconfig python samba shebangfix ssl
- pkg-message:
- For install:
- ======================================================================
ATTENTION - REQUIRED before you run ipa-server-install
======================================================================
>>> Read /usr/local/share/doc/freeipa-server/README.md first,
>>> section "Prerequisites (read this first)".
FreeIPA on FreeBSD uses the MIT Kerberos from ports (security/krb5).
The SASL/GSSAPI plugin that the final "client enrolment" step of
ipa-server-install relies on MUST use that SAME Kerberos - otherwise the
install runs all the way through and then fails at the very end with:
Insufficient access: SASL(-1): generic failure: GSSAPI Error:
... (SPNEGO cannot find mechanisms to negotiate)
or
... Cannot find KDC for realm "EXAMPLE.COM"
By default security/cyrus-sasl2-gssapi is built with GSSAPI_BASE, which
links the BASE-system Kerberos (/usr/lib/libgssapi_krb5) and reads
/etc/krb5.conf - the wrong Kerberos for FreeIPA. You MUST rebuild it with
the GSSAPI_MIT option so it links the ports Kerberos
(/usr/local/lib/libgssapi_krb5) and reads /usr/local/etc/krb5.conf:
* via make.conf (ports / poudriere):
security_cyrus-sasl2-gssapi_SET=GSSAPI_MIT
security_cyrus-sasl2-gssapi_UNSET=GSSAPI_BASE
security_py-gssapi_SET=GSSAPI_MIT
security_py-gssapi_UNSET=GSSAPI_BASE
* or interactively, then rebuild + reinstall the plugin:
make -C /usr/ports/security/cyrus-sasl2-gssapi config
# select GSSAPI_MIT, deselect GSSAPI_BASE
Verify the plugin now links the ports Kerberos:
ldd /usr/local/lib/sasl2/libgssapiv2.so | grep libgssapi_krb5
# MUST show /usr/local/lib/libgssapi_krb5.so
# NOT /usr/lib/libgssapi_krb5.so.*
The Python bindings security/py-gssapi need the same GSSAPI_MIT choice;
ipalib uses them for the kinit during self-enrolment, and with the base
Kerberos the install fails at the very end with "Cannot find KDC".
Note: this is a system-wide choice. All SASL/GSSAPI consumers (SSSD,
OpenLDAP, Postfix, ...) will then use the ports MIT Kerberos - which is
the correct, consistent setup on a host dedicated to FreeIPA.
Full details and the rest of the prerequisites (FQDN, /etc/hosts,
D-Bus/dbus_enable, cloud-init manage_etc_hosts, reboot persistence):
/usr/local/share/doc/freeipa-server/README.md
======================================================================
- Master Sites:
|
| Notes from UPDATING |
- These upgrade notes are taken from /usr/ports/UPDATING
- 2026-08-19
Affects: users of net/freeipa-server and security/dogtag-pki Author: joneum@FreeBSD.org Reason:
net/freeipa-server has been updated to 4.13.2, which also brings
security/dogtag-pki 11.10.1. Two of the changes concern the configuration
of an already deployed pki-tomcat instance, which no package may rewrite:
dogtag-pki now builds with Java 21 instead of Java 17, and FreeIPA
corrects the ACME paths, which used to point at the Linux location
/etc/pki. A server installed from scratch needs none of this. On an
existing one run the following as root, in this order:
# ipactl stop
# pkg upgrade
# sysrc -f /etc/rc.conf.d/pki_tomcatd_pki_tomcat \
pki_tomcatd_pki_tomcat_java_home=/usr/local/openjdk21
# sed -i '' -e 's|/usr/local/openjdk17|/usr/local/openjdk21|' \
/var/db/pki/pki-tomcat/conf/tomcat.conf
# sed -i '' -e 's|/etc/pki/pki-tomcat/|/var/db/pki/pki-tomcat/conf/|g' \
/var/db/pki/pki-tomcat/conf/acme/database.conf \
/var/db/pki/pki-tomcat/conf/acme/realm.conf \
/var/db/pki/pki-tomcat/conf/acme/configsources.conf
# ipa-server-upgrade
# ipactl status
The last command has to list all seven services as RUNNING, and neither of
these two checks may print anything:
# grep openjdk17 /etc/rc.conf.d/pki_tomcatd_pki_tomcat \
/var/db/pki/pki-tomcat/conf/tomcat.conf
# grep -r /etc/pki /var/db/pki/pki-tomcat/conf/acme
A missed JDK change makes pki-tomcatd fail with "UnsupportedClassVersion-
Error: class file version 65.0"; missed ACME paths keep the ACME web
application from starting, which in turn blocks the shutdown of
pki-tomcatd.
|
Number of commits found: 3
| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
4.13.2_1 25 Aug 2026 11:19:54
    |
Jochen Neumeister (joneum)  |
net/freeipa-server: Fix hardcoded paths
ipa-cacert-manage, ipa-getcert and the chrony tools were taken from the
Linux defaults, so they pointed at /usr/sbin, /usr/bin and /etc, where
FreeBSD has nothing. ipa-client-install aborted at the time
synchronisation step for that reason. net/chrony was missing from
RUN_DEPENDS as well.
Reported by: m87carlson (via my private GitHub FreeIPA repository)
Sponsored by: Netzkommune GmbH |
4.13.2 21 Aug 2026 05:42:36
    |
Jochen Neumeister (joneum)  |
net/freeipa-server: Update to 4.13.2
Upstream moved to Codeberg, follow it in MASTER_SITES.
Use the samba framework instead of a hardcoded samba416 dependency [1].
Require sssd2 2.13.1_2 or newer. Earlier revisions leave ${prefix}
unexpanded in SSSDConfig, which makes ipa-server-install fail.
Own the HTTP keytab by www. httpd runs with GSS_USE_PROXY=no and reads
the keytab itself, so a root-owned one left mod_auth_gssapi without
server credentials.
Keep the rc(8) program paths of the Kerberos services in place so a
running kadmind stays visible to rc(8) while it is disabled. Without(Only the first 15 lines of the commit message are shown above ) |
4.13.1 18 Aug 2026 20:41:19
    |
Jochen Neumeister (joneum)  |
net/freeipa-server: Add New Port
FreeIPA is an integrated identity and authentication solution: an LDAP
directory (389 Directory Server), a Kerberos KDC (MIT krb5), a Dogtag
PKI certificate authority and a web UI/CLI, combined into a single managed
domain, the Free Software counterpart to Active Directory.
This port provides the FreeIPA server on FreeBSD together with the
FreeBSD-specific integration that upstream (Linux/systemd oriented) does
not ship: an ipaplatform "freebsd" backend, rc.d service scripts, and
the glue required to run the whole stack against the ports MIT Kerberos
(security/krb5).
WWW: https://www.freeipa.org/
Sponsored by: Netzkommune GmbH |
Number of commits found: 3
|