Using heimdal for AFS authentication without PAM


I am trying to set up an openafs server (Cell A) as a client in a Kerberos 
realm (Real B, B<>A). I have the keytabs with the "host" service for the 
client. I am using Slackware 10.1 and it does not use pam. Setting up pam for 
MIT Kerberos 5 has been a pain so far, and I am looking for a clear alternate 

I was told on a NG that it is possible to use heimdal (as opposed to MIT 
Kerberos 5) to forward authentications to the KDC of realm B (which I do not 
administer) without pam. Is it true ? If so, how does one set it up ?