pingcastle
pingcastle copied to clipboard
Add Certificate Templates to attack path checks
The Certificates Template LDAP object CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=local should be part of critical infrastructure checked by the Attack Path rules (P-ControlPathIndirectEveryone & P-ControlPathIndirectMany).
Write access to this object allows the creation of a certificate template that can allow an attacker to request a certificate for authentication for another (more privileged) user.