Generate AS-REQ with RENEWABLE_OK flag?

Jeffrey Altman jaltman at
Thu Jul 12 14:26:55 EDT 2007

Henry B. Hotz wrote:
> On Jul 12, 2007, at 6:44 AM, Sam Hartman wrote:
>>>>>>> "Henry" == Henry B Hotz <hotz at> writes:
>>     Henry> How do I generate a an AS_REQ with the RENEWABLE_OK flag
>>     Henry> set?
>> for a while now we've set that flag by default.
> That's not what wireshark says.  I'll have to provide more info.

KDC_OPT_RENEWABLE_OK is the default value of [libdefaults]
"kdc_default_options".  The flag is removed if the renew_till value is
non-zero or if KDC_OPT_RENEWABLE is set.

Jeffrey Altman
