Case A36450 · Identity & AD · L4 Advanced
AD Certificate Services Risk
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- AD CS issues certificates that can be used to authenticate to AD via PKINIT, often valid for a year or more
- Misconfigured templates (e.g. requester supplies the subject name + client auth EKU) let users obtain admin certs
- Certificates survive password resets, making them a durable persistence mechanism
- Audit templates and CA settings with Certify/Locksmith-style tools; remove enrollee-supplied subjects
- Treat the CA as Tier 0: its compromise lets an attacker mint trusted authentication certs for anyone
If the interviewer pushes back
- Why does resetting a user password not revoke access gained through a certificate?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.