Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Certificate Templates to attack path checks #199

Open
imaibou opened this issue Nov 9, 2023 · 0 comments
Open

Add Certificate Templates to attack path checks #199

imaibou opened this issue Nov 9, 2023 · 0 comments

Comments

@imaibou
Copy link

imaibou commented Nov 9, 2023

The Certificates Template LDAP object CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=local should be part of critical infrastructure checked by the Attack Path rules (P-ControlPathIndirectEveryone & P-ControlPathIndirectMany).

Write access to this object allows the creation of a certificate template that can allow an attacker to request a certificate for authentication for another (more privileged) user.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant