Skip to main content
Version: 2.2.1-preview

AD-CFG-15 - Enrollment CA certificate details should be retrievable

Overviewโ€‹

Enrollment-capable CA certificates include validity periods and other critical properties. Expired or invalid CA certificates can break certificate issuance and domain authentication flows. In addition, unexpected certificate replacements (e.g., unknown thumbprints) can indicate PKI tampering.

Security Recommendationโ€‹

  • Monitor CA certificate expiration and rotate certificates through an approved operational process.
  • Validate certificate thumbprints/subjects/issuers against your known-good CA configuration.
  • Alert when CA certificates are within your rotation window (commonly 30/60 days, depending on your policy).
  • Ensure CRL/OCSP and publication settings remain correct after certificate updates.

How the Test Worksโ€‹

  • Enumerates enrollment-capable CA objects in Active Directory.
  • Retrieves CA certificate details associated with those enrollment services.
  • Evaluates certificate validity (e.g., already expired, or expiring soon based on your configured thresholds) and highlights unexpected certificate identity details.

Test Metadataโ€‹

FieldValue
Test IDAD-CFG-15
SeverityInfo
SuiteActive Directory
CategoryAD.Config
PowerShell testTest-MtAdEnrollmentCaCertificateDetails
TagsAD, AD-CFG-15, AD.Config

Sourceโ€‹

  • Pester test: tests/ad/config/Test-MtAdEnrollmentCaCertificateDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/config/Test-MtAdEnrollmentCaCertificateDetails.ps1