SECURITY UPDATE: Samba AD DC did not enforce the Validated-DNS-Host-Name
write right, allowing an unprivileged authenticated user with machine
account write access (e.g. SeMachineAccountPrivilege) to set the
dNSHostName attribute to an arbitrary value, bypassing the MS-ADTS
requirement that it match <sAMAccountName-sans-$>.<dnsDomainName>.
This primitive is commonly chained with CVE-2022-26923 (Certifried) via
AD CS to forge a machine certificate and escalate to Domain Admin.