
PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.
PowerShell toolkit for auditing Active Directory Certificate Services (AD CS).
It is built on top of PKISolution's PSPKI toolkit (Microsoft Public License). This repo contains a newer version of PSPKI than what's available in the PSGallery (see the PSPKI directory). Vadims Podans (the creator of PSPKI) graciously provided this version as it contains patches for several bugs.
This README is only meant as a starting point- for complete details and defensive guidance, please see the "Certified Pre-Owned" whitepaper.
The module contains the following main functions:
WARNING: This code is beta! We are confident that Invoke-PKIAudit will not impact the environment as the amount of data it queries is quite limited. We have not done rigorous testing with Get-CertRequest against typical CA server workloads. Get-CertRequest queries the CA's database directly and may have to process thousands of results, which might impact performance.
IF THERE ARE NO RESULTS, THIS IS NOT A GUARANTEE THAT YOUR ENVIRONMENT IS SECURE!!
WE ALSO CANNOT GUARANTEE THAT OUR MITIGATION ADVICE WILL MAKE YOUR ENVIRONMENT SECURE OR WILL NOT DISRUPT OPERATIONS!
It is your responsibility to talk to your Active Directory/PKI/Architecture team(s) to determine the best mitigations for your environment.
If the code breaks, or we missed something, please submit an issue or pull request for a fix!
Install the following on a Windows machine using an elevated PowerShell prompt (PowerShell verion 5.1 or above):
Get-WindowsCapability -Online -Name "Rsat.*" | where Name -match "CertificateServices|ActiveDirectory" | Add-WindowsCapability -Online
Install-Module -Name PSPKI
Download the module extract it to a folder. Then, import the module using the following commands:
cd PSPKIAudit
Get-ChildItem -Recurse | Unblock-File
Import-Module .\PSPKIAudit.psd1
Running Invoke-PKIAudit will run all auditing checks against AD CS in the current domain, including enumerating various Certificate Authority and Certificate Template settings. To audit a specific CA, you can run Invoke-PKIAudit -CAComputerName CA.DOMAIN.COM or Invoke-PKIAudit -CAName X-Y-Z.
Any misconfigurations (ESC1-8) will appear as properties on the CA/template results displayed to identify the specific misconfiguration found.
If you want to change the groups/users used to test enrollment/access control, modify the $CommonLowprivPrincipals regex at the top of Invoke-PKIAudit.ps1
If you want to export all CA information to a csv, run: Get-AuditCertificateAuthority [-CAComputerName CA.DOMAIN.COM | -CAName X-Y-Z] | Export-Csv -NoTypeInformation CAs.csv
If you want to export ALL published template information to a csv (not just vulnerable templates), run: Get-AuditCertificateTemplate [-CAComputerName CA.DOMAIN.COM | -CAName X-Y-Z] | Export-Csv -NoTypeInformation templates.csv
There are two main sections of output, details about discovered CAs and details about potentially vulnerable templates.
For certificate authority results:
| Certificate Authority Property | Description |
|---|---|
| ComputerName | The system the CA is running on. |
| CAName | The name of the CA. |
| ConfigString | The full COMPUTER\CA_NAME configuration string. |
| IsRoot | If the CA is a root CA. |
| AllowsUserSuppliedSans | If the CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set. |
| VulnerableACL | Whether the CA has a vulnerable ACL setting. |
| EnrollmentPrincipals | Principals who have the Enroll privilege at the CA level. |
| EnrollmentEndpoints | The CA's web services enrollment endpoints. |
| NTLMEnrollmentEndpoints | The CA's web services enrollment endpoints that have NTLM enabled. |
| DACL | The full access control information. |
| Misconfigurations | ESCX indicating the specific misconfiguration present (if any). |
For certificate template results: