daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (9992B)


      1 ---
      2 title: "AD Certificates"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/ad-certificates/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/ad-certificates/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # AD Certificates
     14 
     15 ## Introduction
     16 
     17 ### Components of a Certificate
     18 
     19 - The **Subject** of the certificate denotes its owner.
     20 - A **Public Key** is paired with a privately held key to link the certificate to its rightful owner.
     21 - The **Validity Period**, defined by **NotBefore** and **NotAfter** dates, marks the certificate's effective duration.
     22 - A unique **Serial Number**, provided by the Certificate Authority (CA), identifies each certificate.
     23 - The **Issuer** refers to the CA that has issued the certificate.
     24 - **SubjectAlternativeName** allows for additional names for the subject, enhancing identification flexibility.
     25 - **Basic Constraints** identify if the certificate is for a CA or an end entity and define usage restrictions.
     26 - **Extended Key Usages (EKUs)** delineate the certificate's specific purposes, like code signing or email encryption, through Object Identifiers (OIDs).
     27 - The **Signature Algorithm** specifies the method for signing the certificate.
     28 - The **Signature**, created with the issuer's private key, guarantees the certificate's authenticity.<sup>[[1]](#references)</sup>
     29 
     30 ### Special Considerations
     31 
     32 - **Subject Alternative Names (SANs)** expand a certificate's applicability to multiple identities, crucial for servers with multiple domains. Secure issuance processes are vital to avoid impersonation risks by attackers manipulating the SAN specification.<sup>[[1]](#references)</sup>
     33 
     34 ### Certificate Authorities (CAs) in Active Directory (AD)
     35 
     36 AD CS acknowledges CA certificates in an AD forest through designated containers, each serving unique roles:<sup>[[1]](#references)</sup>
     37 
     38 - **Certification Authorities** container holds trusted root CA certificates.
     39 - **Enrolment Services** container details Enterprise CAs and their certificate templates.
     40 - **NTAuthCertificates** object includes CA certificates authorized for AD authentication.
     41 - **AIA (Authority Information Access)** container facilitates certificate chain validation with intermediate and cross CA certificates.
     42 
     43 ### Certificate Acquisition: Client Certificate Request Flow
     44 
     45 1. The request process begins with clients finding an Enterprise CA.
     46 2. A CSR is created, containing a public key and other details, after generating a public-private key pair.
     47 3. The CA assesses the CSR against available certificate templates, issuing the certificate based on the template's permissions.
     48 4. Upon approval, the CA signs the certificate with its private key and returns it to the client.<sup>[[1]](#references)</sup>
     49 
     50 ### Certificate Templates
     51 
     52 Defined within AD, these templates outline the settings and permissions for issuing certificates, including permitted EKUs and enrollment or modification rights, critical for managing access to certificate services.<sup>[[1]](#references)</sup>
     53 
     54 ## Certificate Enrollment
     55 
     56 The enrollment process for certificates is initiated by an administrator who **creates a certificate template**, which is then **published** by an Enterprise Certificate Authority (CA). This makes the template available for client enrollment, a step achieved by adding the template's name to the `certificatetemplates` field of an Active Directory object.<sup>[[1]](#references)</sup>
     57 
     58 For a client to request a certificate, **enrollment rights** must be granted. These rights are defined by security descriptors on the certificate template and the Enterprise CA itself. Permissions must be granted in both locations for a request to be successful.<sup>[[1]](#references)</sup>
     59 
     60 ### Template Enrollment Rights
     61 
     62 These rights are specified through Access Control Entries (ACEs), detailing permissions like:<sup>[[1]](#references)</sup>
     63 
     64 - **Certificate-Enrollment** and **Certificate-AutoEnrollment** rights, each associated with specific GUIDs.
     65 - **ExtendedRights**, allowing all extended permissions.
     66 - **FullControl/GenericAll**, providing complete control over the template.
     67 
     68 ### Enterprise CA Enrollment Rights
     69 
     70 The CA's rights are outlined in its security descriptor, accessible via the Certificate Authority management console. Some settings even allow low-privileged users remote access, which could be a security concern.<sup>[[1]](#references)</sup>
     71 
     72 ### Additional Issuance Controls
     73 
     74 Certain controls may apply, such as:<sup>[[1]](#references)</sup>
     75 
     76 - **Manager Approval**: Places requests in a pending state until approved by a certificate manager.
     77 - **Enrolment Agents and Authorized Signatures**: Specify the number of required signatures on a CSR and the necessary Application Policy OIDs.
     78 
     79 ### Methods to Request Certificates
     80 
     81 Certificates can be requested through:<sup>[[1]](#references)</sup>
     82 
     83 1. **Windows Client Certificate Enrollment Protocol** (MS-WCCE), using DCOM interfaces.
     84 2. **ICertPassage Remote Protocol** (MS-ICPR), through named pipes or TCP/IP.
     85 3. The **certificate enrollment web interface**, with the Certificate Authority Web Enrollment role installed.
     86 4. The **Certificate Enrollment Service** (CES), in conjunction with the Certificate Enrollment Policy (CEP) service.
     87 5. The **Network Device Enrollment Service** (NDES) for network devices, using the Simple Certificate Enrollment Protocol (SCEP).
     88 
     89 Windows users can also request certificates via the GUI (`certmgr.msc` or `certlm.msc`) or command-line tools (`certreq.exe` or PowerShell's `Get-Certificate` command).
     90 
     91 ```bash
     92 # Example of requesting a certificate using PowerShell
     93 Get-Certificate -Template "User" -CertStoreLocation "cert:\\CurrentUser\\My"
     94 ```
     95 
     96 ## Certificate Authentication
     97 
     98 Active Directory (AD) supports certificate authentication, primarily utilizing **Kerberos** and **Secure Channel (Schannel)** protocols.<sup>[[1]](#references)</sup>
     99 
    100 ### Kerberos Authentication Process
    101 
    102 In the Kerberos authentication process, a user's request for a Ticket Granting Ticket (TGT) is signed using the **private key** of the user's certificate. This request undergoes several validations by the domain controller, including the certificate's **validity**, **path**, and **revocation status**. Validations also include verifying that the certificate comes from a trusted source and confirming the issuer's presence in the **NTAUTH certificate store**. Successful validations result in the issuance of a TGT. The **`NTAuthCertificates`** object in AD, found at:
    103 
    104 ```bash
    105 CN=NTAuthCertificates,CN=Public Key Services,CN=Services,CN=Configuration,DC=<domain>,DC=<com>
    106 ```
    107 
    108 is central to establishing trust for certificate authentication.<sup>[[1]](#references)</sup>
    109 
    110 ### Secure Channel (Schannel) Authentication
    111 
    112 Schannel facilitates secure TLS/SSL connections, where during a handshake, the client presents a certificate that, if successfully validated, authorizes access.<sup>[[2]](#references)</sup> The mapping of a certificate to an AD account may involve Kerberos’s **S4U2Self** function or the certificate’s **Subject Alternative Name (SAN)**, among other methods.<sup>[[1]](#references)</sup>
    113 
    114 ### AD Certificate Services Enumeration
    115 
    116 AD's certificate services can be enumerated through LDAP queries, revealing information about **Enterprise Certificate Authorities (CAs)** and their configurations. This is accessible by any domain-authenticated user without special privileges.<sup>[[1]](#references)</sup> Tools like **[Certify](https://github.com/GhostPack/Certify)** and **[Certipy](https://github.com/ly4k/Certipy)** are used for enumeration and vulnerability assessment in AD CS environments.<sup>[[3]](#references)</sup>
    117 
    118 Commands for using these tools include:
    119 
    120 ```bash
    121 # Enumerate trusted root CA certificates, Enterprise CAs and HTTP enrollment endpoints
    122 # Useful flags: /domain, /path, /hideAdmins, /showAllPermissions, /skipWebServiceChecks
    123 Certify.exe cas [/ca:SERVER\ca-name | /domain:domain.local | /path:CN=Configuration,DC=domain,DC=local] [/hideAdmins] [/showAllPermissions] [/skipWebServiceChecks]
    124 
    125 # Identify vulnerable certificate templates and filter for common abuse cases
    126 Certify.exe find
    127 Certify.exe find /vulnerable [/currentuser]
    128 Certify.exe find /enrolleeSuppliesSubject   # ESC1 candidates (CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT)
    129 Certify.exe find /clientauth                # templates with client-auth EKU
    130 Certify.exe find /showAllPermissions        # include template ACLs in output
    131 Certify.exe find /json /outfile:C:\Temp\adcs.json
    132 
    133 # Enumerate PKI object ACLs (Enterprise PKI container, templates, OIDs) – useful for ESC4/ESC7 discovery
    134 Certify.exe pkiobjects [/domain:domain.local] [/showAdmins]
    135 
    136 # Use Certipy for enumeration and identifying vulnerable templates
    137 certipy find -vulnerable -u john@corp.local -p Passw0rd -dc-ip 172.16.126.128
    138 
    139 # Enumerate Enterprise CAs and certificate templates with certutil
    140 certutil.exe -TCAInfo
    141 certutil -v -dstemplate
    142 ```
    143 
    144 Rubeus can also use a password-protected PFX certificate for PKINIT authentication and request a TGT. The optional `/getcredentials` switch requests a U2U service ticket and attempts to recover the account NT hash:<sup>[[4]](#references)</sup>
    145 
    146 ```powershell
    147 Rubeus.exe asktgt /user:<USER> /certificate:C:\temp\leaked.pfx /password:<PFX_PASSWORD> /getcredentials /ptt
    148 ```
    149 
    150 ## References
    151 
    152 - [1] [Certified Pre-Owned: Abusing Active Directory Certificate Services](https://www.specterops.io/assets/resources/Certified_Pre-Owned.pdf)
    153 - [2] [What Is SSL/TLS Client Authentication & How Does It Work?](https://comodosslstore.com/blog/what-is-ssl-tls-client-authentication-how-does-it-work.html)
    154 - [3] [GhostPack/Certify](https://github.com/GhostPack/Certify)
    155 - [4] [GhostPack/Rubeus](https://github.com/GhostPack/Rubeus)