net ads join when using a precreated computer object and using credentials from a different domain does not add the SPN or DNS attributes

Andreas Schneider asn at
Mon Jul 1 05:52:31 MDT 2013

On Friday 28 June 2013 10:16:23 Richard Sharpe wrote:
> Hi folks,

> With Samba 3.6.x net ads join we are seeing cases where if you join
> with a pre-created computer object and use credentials from a
> different domain in the AD forest, the SPN and DNS attributes are not
> added to the computer object.

'net ads join' even overwrites all servicePrincipleNames already set in AD


'net ads keytab create' doesn't lookup SPNs in AD.

So you need a new function to lookup SPNs in AD which is needed by both 
functions. It makes sense to work on both bugs at the same time.

If you have time to work on this it would be much appreciated, else it needs 
to wait till I have time for it.

	-- andreas

Andreas Schneider                   GPG-ID: F33E3FC6
Samba Team                             asn at

More information about the samba-technical mailing list