kerberos tickets and the SPNs

Markus Moeller huaraz at
Fri May 8 17:34:22 EDT 2009

I use also msktutil and you can find it here

You can also use setspn -A host/fqdn in lowercase. instead of setspn -R.

BTW the original netjoin tool from MS used computer accounts not user 
I don't know why they changed their mind.


----- Original Message ----- 
From: "Ravi Channavajhala" <ravi.channavajhala at>
To: "Douglas E. Engert" <deengert at>
Cc: "Markus Moeller" <huaraz at>; <kerberos at>
Sent: Friday, May 08, 2009 8:59 PM
Subject: Re: kerberos tickets and the SPNs

Don't agree here.  Natively adding a computer to AD and checking with
setspn -L didn't show any SPNs.  Resetting the SPNs with setspn -R,
creates two entries


Both are incorrect....

The point is, I can manipulate SPNs to no end, but obviously no
success with Kerberos. My real issue is kerberos flip flopping with
'Server not found in Database' to 'Keytable entry incorrect Key

More information about the Kerberos mailing list