NACSA licence in progress
← All WhitepapersADCS · PKI Defense22 Pages⏱️ 17 min read

ADCS Attack-Surface Reduction & PKI Security Guide (ESC1–ESC14)

Hardening Enterprise Public Key Infrastructure Against Golden Certificate Takeover

AuthornCrypt Offensive Security PracticeSenior Identity Security Researcher (CRTE, OSCP, CRTP)
Peer Reviewed ByIdentity & Cryptography LeadPKI Infrastructure Specialist
Last Updated

Executive Decision Brief

Active Directory Certificate Services (ADCS) is frequently overlooked during security assessments, yet misconfigured certificate templates provide attackers with direct, stealthy escalation paths from unprivileged domain users to Domain Admin. This guide provides step-by-step remediation for all known ADCS abuse vectors (ESC1 through ESC14).

Strategic Takeaways for Executive Leadership:

  • Audits and remediates certificate templates permitting enrollee-supplied Subject Alternative Names (SANs - ESC1).
  • Secures web enrollment endpoints against NTLM relaying attacks (ESC8) via Extended Protection for Authentication (EPA).
  • Prevents persistent domain persistence through forged Golden Certificates (PKINIT authentication abuse).
  • Provides PowerShell and Certify audit scripts to continuously detect misconfigured certificate templates.

Target Executive Audience:

Windows Infrastructure & Identity EngineersPKI Administrators and Certificate Authorities LeadsRed Team and Purple Team PractitionersEnterprise Threat Hunters and SOC Analysts

Misconfigured Certificate Templates Allow Low-Privilege Users to Request Valid Domain Admin Certificates

When an ADCS certificate template is configured with client authentication capabilities and allows enrollees to specify a Subject Alternative Name (SAN), any low-privilege domain user can request a certificate in the name of the Domain Administrator.

The attacker then uses Kerberos PKINIT authentication to exchange the forged certificate for a Domain Admin Ticket-Granting Ticket (TGT), achieving full domain compromise in seconds without triggering standard password monitoring alerts.

Exhibit 1: ADCS Misconfiguration Vector (ESC1–ESC8) Remediation ReferencePrimary ADCS vulnerabilities and exact hardening controls.
Abuse IDRoot-Cause MisconfigurationRequired Remediation Action
ESC1Template allows enrollee-supplied SAN + Client Auth EKU + Broad enrollment rightsDisable 'Supply in the request'; enforce CA manager approval on high-privilege templates
ESC2 / ESC3Any Purpose EKU or Certificate Request Agent abuseRestrict enrollment agent issuance policies and eliminate unconstrained EKUs
ESC4Misconfigured ACLs on certificate templates allowing low-privilege modificationAudit template write ACLs; remove write permissions for Authenticated Users
ESC8ADCS Web Enrollment HTTP endpoints allowing unauthenticated NTLM relayEnforce HTTPS, disable NTLM authentication, and enable Extended Protection for Authentication (EPA)
Statutory Crosswalk

Regulatory & Framework Mapping

Exact alignment of technical requirements to Bank Negara Malaysia, NACSA, and international standards.

Framework & ClauseMandatory ObligationnCrypt Solution CapabilityAudit Evidence Deliverable
BNM RMiTSection 10.23Robust identity authentication and prevention of unauthorized privilege escalationADCS Technical Audit & Automated Template HardeningADCS Vulnerability Assessment Report & Template Remediation Script Package
Procurement Evaluation

RFP Scoping & Vendor Due Diligence Checklist

Criteria for technical evaluation committees assessing external cybersecurity service providers in Malaysia.

PKI Tooling

✓ Mandatory Pass Criteria:Assessment uses advanced PKI auditing tools (e.g. Certify, PKIAudit) to inspect all active templates and enrollment endpoints
✕ Procurement Red Flags:Standard vulnerability scan report that completely skips ADCS enumeration
Recommended RFP Question: "Does your active directory assessment include full-scope enumeration of ADCS certificate templates and NTLM relay endpoints?"
FAQ

Executive & Technical Questions

Why are ADCS vulnerabilities particularly dangerous?

Because certificate-based authentication generates legitimate Kerberos tickets directly from the Domain Controller, leaving no password-guessing or hash-cracking logs in the event viewer.

Disclaimer: This whitepaper is published for strategic decision-support and technical guidance. It does not constitute formal legal counsel. Malaysian enterprises should validate specific statutory interpretations with qualified counsel.

Accreditation Context: nCrypt uses CREST-aligned methodologies and deploys certified practitioners (OSCP, CRTO, CISA, CISSP). NACSA Cybersecurity Service Provider (CSP) license application submitted; ISO/IEC 27001 audit in progress.

Need a Technical Scoping Session?

Speak directly with our senior offensive and regulatory specialists to map your specific compliance requirements and threat profile before going to procurement.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.