bytewreck
e7e56ff9b0
Fixed private key conversion issue on Windows Server 2012
2025-08-19 10:40:35 +02:00
bytewreck
f707ad061f
Fixed PKCS10 extension cast issue on Server 2012
2025-08-19 10:18:19 +02:00
bytewreck
bb7e8f272b
Extended exception coverage
2025-08-19 10:10:10 +02:00
bytewreck
c395f060a3
Added disarmed build
2025-08-12 11:36:15 +02:00
bytewreck
1789f78bfc
Removed test code
2025-08-12 00:10:20 +02:00
bytewreck
4894c2ccdc
Upgrade to 2.0
2025-08-11 20:12:40 +02:00
JonasBK
0791087289
feat: SAN url
2024-08-12 03:57:32 -07:00
Berkeley Churchill
a0315dfb01
fix null reference
...
check that template.ApplicationPolicies is non-null
2023-01-09 00:26:01 +02:00
HarmJ0y
48ef2b49b8
Merge branch 'main' of https://github.com/GhostPack/Certify
2022-11-08 16:26:49 -08:00
HarmJ0y
71636c435f
Added /sidextension flag to the request command
...
Added `/sidextension` flag to the `request` command
2022-11-08 16:26:31 -08:00
Will
8b898b78ab
Merge pull request #22 from LuemmelSec/main
...
For ESC 3 the 2nd requirement is not evaluated
2022-11-08 16:24:54 -08:00
Lee Christensen
b28142c20e
remove checking auto-enrollment permissions
2022-11-02 16:27:21 -07:00
Lee Christensen
afd8932575
more verbose errors
2022-11-02 15:44:29 -07:00
Lee Christensen
eaca963bc3
fix bug in parsing cert name flag
2022-10-24 07:40:12 -07:00
Lynden L
b25b87f1f8
Update Find.cs
...
Fix the errors of "error CS8629: Nullable value type may be null."
2022-09-19 11:58:49 -07:00
LuemmelSec
39058911bd
Update CommonOids.cs
2022-09-18 11:15:44 +02:00
LuemmelSec
babadc9ed4
Update Find.cs
2022-09-18 11:15:03 +02:00
CCob
e754228d1d
Templates with DISABLE_EMBED_SID + DNS subject now marked as vulnerable (ESC9)
...
As part of the mitigation for CVE-2022-26923, Microsoft introduced a new certificate attribute OID that embeds the original account SID that requested the certificate. Microsoft also introduced a new template flag CT_FLAG_NO_SECURITY_EXTENSION (0x80000) that disables embedding this new certificate attribute. Therefore a new check has been added dubbed ESC9 that checks for the presence of this flag along with SUBJECT_ALT_REQUIRE_DNS or SUBJECT_REQUIRE_DNS_AS_CN set within the name flag.
2022-05-11 09:29:28 +01:00
michiellemmens
2765967dad
Update Find.cs
2021-12-16 16:05:01 +01:00
Lee Christensen
4bea33ae2d
added warning when /machine not specified
2021-12-10 11:33:15 -08:00
leechristensen
da3e11dac7
made entry methods public
2021-10-11 17:51:04 -07:00
Lee Christensen
e8d6ecbaed
Merge pull request #5 from SAERXCIT/option-ldapserver
...
Allow specifying LDAP server
2021-10-05 23:14:13 -07:00
leechristensen
4c24a83552
add dnMerge and fix interop errors
2021-10-05 23:02:47 -07:00
leechristensen
cebdfdb8e5
fix nullable type errors
2021-10-05 20:34:50 -07:00
daem0nc0re
85c0bcca94
Add mspki-certificate-application-policy output and fix comment
2021-10-04 20:06:17 +09:00
SAERXCIT
24a4d285cc
Allow specifying LDAP server
2021-08-30 22:40:40 +02:00
HarmJ0y
2b1530309c
BlackHat release
...
BlackHat release
2021-08-04 16:44:25 -07:00