NOTES
Certipy turns ADCS configuration into testable relationships: certificate authorities, templates, enrollment rights, issuance requirements, authentication EKUs, web enrollment, and account mapping.
The important question is not whether a template receives an ESC label. It is whether the controlled principal can satisfy every prerequisite and obtain authentication material for a more privileged identity.
VALIDATION
- Synchronize time with the domain before troubleshooting Kerberos or certificate requests.
- Enumerate CAs, templates, permissions, enrollment services, and configuration.
- Identify the controlled principal and verify effective enrollment rights.
- Trace each required condition from template configuration to certificate request to authentication.
- Use the least invasive proof that demonstrates the privilege change.
- Document template, CA, requester, requested identity, certificate result, and final authenticated context.
COMMANDS
certipy find -u USER@DOMAIN -p PASSWORD -dc-ip DC_IP -enabled -vulnerable
certipy req -u USER@DOMAIN -p PASSWORD -ca CA_NAME -template TEMPLATE
certipy auth -pfx identity.pfx -dc-ip DC_IP
GOTCHAS
- A denied request may indicate enrollment permissions, manager approval, signatures, template publication, or CA targeting—not that the theory is wrong.
- ESC categories have prerequisites; record which exact condition is satisfied.
- Protect generated PFX files as credentials and remove them according to the engagement plan.
- Validate remediation against effective permissions and template behavior, not only a GUI checkbox.