kerberos-prefix-commands in heimdal by default

I have turned on kerberos-prefix-commands in security/heimdal by default.

Having kerberos *support* is great, but installing "su" that shadows
system su violates the Principle of Least Astonishment.

People are ending up with heimdal not because they are at a kerberos
site and want it, but because some other package wants kerberos support.
I am guessing that the ratio of "why is su broken" to "I want su to be
the kerberos version" is over 1000:1.

