27 Commits
Author SHA1 Message Date
bytewreck e7e56ff9b0 Fixed private key conversion issue on Windows Server 2012 2025-08-19 10:40:35 +02:00
bytewreck f707ad061f Fixed PKCS10 extension cast issue on Server 2012 2025-08-19 10:18:19 +02:00
bytewreck bb7e8f272b Extended exception coverage 2025-08-19 10:10:10 +02:00
bytewreck c395f060a3 Added disarmed build 2025-08-12 11:36:15 +02:00
bytewreck 1789f78bfc Removed test code 2025-08-12 00:10:20 +02:00
bytewreck 4894c2ccdc Upgrade to 2.0 2025-08-11 20:12:40 +02:00
JonasBK 0791087289 feat: SAN url 2024-08-12 03:57:32 -07:00
Berkeley Churchill a0315dfb01 fix null reference
check that template.ApplicationPolicies is non-null
2023-01-09 00:26:01 +02:00
HarmJ0y 48ef2b49b8 Merge branch 'main' of https://github.com/GhostPack/Certify 2022-11-08 16:26:49 -08:00
HarmJ0y 71636c435f Added /sidextension flag to the request command
Added `/sidextension` flag to the `request` command
2022-11-08 16:26:31 -08:00
Will 8b898b78ab Merge pull request #22 from LuemmelSec/main
For ESC 3 the 2nd requirement is not evaluated
2022-11-08 16:24:54 -08:00
Lee Christensen b28142c20e remove checking auto-enrollment permissions 2022-11-02 16:27:21 -07:00
Lee Christensen afd8932575 more verbose errors 2022-11-02 15:44:29 -07:00
Lee Christensen eaca963bc3 fix bug in parsing cert name flag 2022-10-24 07:40:12 -07:00
Lynden L b25b87f1f8 Update Find.cs
Fix the errors of "error CS8629: Nullable value type may be null."
2022-09-19 11:58:49 -07:00
LuemmelSec 39058911bd Update CommonOids.cs 2022-09-18 11:15:44 +02:00
LuemmelSec babadc9ed4 Update Find.cs 2022-09-18 11:15:03 +02:00
CCob e754228d1d Templates with DISABLE_EMBED_SID + DNS subject now marked as vulnerable (ESC9)
As part of the mitigation for CVE-2022-26923, Microsoft introduced a new certificate attribute OID that embeds the original account SID that requested the certificate.  Microsoft also introduced a new template flag CT_FLAG_NO_SECURITY_EXTENSION (0x80000) that disables embedding this new certificate attribute.  Therefore a new check has been added dubbed ESC9 that checks for the presence of this flag along with SUBJECT_ALT_REQUIRE_DNS or SUBJECT_REQUIRE_DNS_AS_CN set within the name flag.
2022-05-11 09:29:28 +01:00
michiellemmens 2765967dad Update Find.cs 2021-12-16 16:05:01 +01:00
Lee Christensen 4bea33ae2d added warning when /machine not specified 2021-12-10 11:33:15 -08:00
leechristensen da3e11dac7 made entry methods public 2021-10-11 17:51:04 -07:00
Lee Christensen e8d6ecbaed Merge pull request #5 from SAERXCIT/option-ldapserver
Allow specifying LDAP server
2021-10-05 23:14:13 -07:00
leechristensen 4c24a83552 add dnMerge and fix interop errors 2021-10-05 23:02:47 -07:00
leechristensen cebdfdb8e5 fix nullable type errors 2021-10-05 20:34:50 -07:00
daem0nc0re 85c0bcca94 Add mspki-certificate-application-policy output and fix comment 2021-10-04 20:06:17 +09:00
SAERXCIT 24a4d285cc Allow specifying LDAP server 2021-08-30 22:40:40 +02:00
HarmJ0y 2b1530309c BlackHat release
BlackHat release
2021-08-04 16:44:25 -07:00