pingcastle icon indicating copy to clipboard operation
pingcastle copied to clipboard

Add Certificate Templates to attack path checks

Open imaibou opened this issue 2 years ago • 0 comments

The Certificates Template LDAP object CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=local should be part of critical infrastructure checked by the Attack Path rules (P-ControlPathIndirectEveryone & P-ControlPathIndirectMany).

Write access to this object allows the creation of a certificate template that can allow an attacker to request a certificate for authentication for another (more privileged) user.

imaibou avatar Nov 09 '23 09:11 imaibou