Open cardosec

Case A36450 · Identity & AD · L4 Advanced

AD Certificate Services Risk

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. AD CS issues certificates that can be used to authenticate to AD via PKINIT, often valid for a year or more
  2. Misconfigured templates (e.g. requester supplies the subject name + client auth EKU) let users obtain admin certs
  3. Certificates survive password resets, making them a durable persistence mechanism
  4. Audit templates and CA settings with Certify/Locksmith-style tools; remove enrollee-supplied subjects
  5. Treat the CA as Tier 0: its compromise lets an attacker mint trusted authentication certs for anyone

If the interviewer pushes back

  • Why does resetting a user password not revoke access gained through a certificate?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.