AD-CFG-19 - Intermediate CA details should be retrievable
Overviewβ
Intermediate CA certificates define the intermediate links used to build trust chains from trusted roots to issued certificates. If intermediate CA certificates expire, misconfigured, or unauthorized certificates are added, certificate chain validation can fail and authentication may break.
This test concentrates on intermediate CA details (including certificate validity) to help detect:
- Expired or soon-to-expire intermediate CAs that will break certificate chains
- Unexpected/unauthorized intermediates that expand who can issue certificates
Security Recommendationβ
- Confirm each intermediate CA certificate is part of your approved PKI hierarchy.
- Remove unauthorized intermediates and ensure only valid chain-building intermediates are retained.
- Set renewal timelines and alerting for intermediates approaching expiration.
- If you rotate intermediates, validate that dependent relying parties and AD-integrated flows continue to validate.
How the Test Worksβ
The test enumerates intermediate CA certificates in the AD configuration context, extracts relevant identifiers (e.g., subject/issuer and thumbprint) and validity periods, and reports whether each intermediate is within the expected valid timeframe.
Related Testsβ
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-CFG-19 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdIntermediateCaDetails |
| Tags | AD, AD-CFG-19, AD.Config |
Sourceβ
- Pester test:
tests/ad/config/Test-MtAdIntermediateCaDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdIntermediateCaDetails.ps1

