Generate AS-REQ with RENEWABLE_OK flag?

Jeffrey Altman jaltman at
Thu Jul 12 15:18:35 EDT 2007

Henry B. Hotz wrote:
> I was explicitly setting both the lifetime and the renew lifetime
> options in the request.  Trying to manually recreate a request like
> Solaris pam_krb5 makes, since that's so awkward to set up.  What
> you're saying is that RENEWABLE_OK goes away as soon as you try to be
> explicit for debugging.  P-(
I'm saying that KDC_OPT_RENEWABLE and KDC_OPT_RENEWABLE_OK should not be
set at the same time.  If you explicitly ask for a renewable ticket by
setting a renew_till time, then KDC_OPT_RENEWABLE_OK will not be sent.

