I have heimdal kerberos 5 emerged that satisfies: virtual/krb5 app-crypt/heimdal emergeing openldap-2.1.26 afterward with USE="kerberos" causes mit-krb5 to trample the heimdal install. I know openldap works with heimdal but the ebuild breaks it. My solution is to unemerge mit-krb5 and reemerge heimdal after openldap is emerged.
deps in 2.1.27 changed to virtual/krb5.