Skip to content

fix(detection): populate editor properties on CA objects for ESC5a - #112

Merged
jakehildreth merged 1 commit into
mainfrom
fix/esc5a-ca-editor-detection
Oct 7, 2026
Merged

jakehildreth merged 1 commit into
mainfrom
fix/esc5a-ca-editor-detection

Conversation

@jakehildreth

Copy link
Copy Markdown
Owner

What

pKIEnrollmentService objects (CAs) could never produce an ESC5a finding. The CA enrichment pipeline in Initialize-AdcsObjectStore never ran Set-DangerousEditor / Set-LowPrivilegeEditor, so DangerousEditor and LowPrivilegeEditor stayed empty — and ESC5a's definition reads exactly those two EditorProperties. Result: even a CA with Authenticated Users / GenericAll on its DACL was invisible to ESC5a.

Templates and non-CA infrastructure objects did run the editor checks, which is why ESC5a only ever fired on those (e.g. the AIA object) and never on a CA.

The change

         Set-Owner |
-        Set-HasNonStandardOwner
+        Set-HasNonStandardOwner |
+        Set-DangerousEditor |
+        Set-LowPrivilegeEditor

Two enrichment steps added to the CA pipeline in Private/Initialize/Initialize-AdcsObjectStore.ps1. Carried-forward gap: the pre-refactor Invoke-Locksmith2 had the same split; 55ddc6d extracted it verbatim.

Before / After

Scanned live against adcs.goat, target CN=LabRootCA1,CN=Enrollment Services,...,DC=adcs,DC=goat — which has NT AUTHORITY\Authenticated Users | GenericAll | Allow (direct ACE).

DangerousEditor ESC5a on LabRootCA1
Before [] not flagged (1 issue total, on an AIA object)
After [S-1-5-11] Authenticated Users / GenericAll flagged

After: 3 ESC5a issues on LabRootCA1 (Authenticated Users / GenericAll, plus the CA machine account ADCSGOAT-CA$ twice — a separate low-priv-editor finding).

Detection gates confirmed sound in isolation: Test-IsDangerousAce matches GenericAll for pKIEnrollmentService, and S-1-5-11 is a DangerousPrincipal. The ACE itself was always detectable; the object just never got the enrichment.

Risk

Low. Additive enrichment to one pipeline branch — no interface changes, no behavior change for templates or other objects. Easily reverted.

Notes

  • Module version bumped to 2026.10.61822 (CalVer).
  • The scan still logs Set-CADisableExtensionList : Get-PSCDisableExtensionList cmdlet not found (missing optional PSCertutil dependency) — pre-existing, unrelated to this fix, non-fatal to the CA pipeline. Worth a follow-up issue if you want that dependency stubbed or made optional.

- add Set-DangerousEditor and Set-LowPrivilegeEditor to the CA pipeline in Initialize-AdcsObjectStore
- CAs (pKIEnrollmentService) were routed through the CA branch which never ran editor checks, leaving DangerousEditor/LowPrivilegeEditor empty
- ESC5a reads EditorProperties (DangerousEditor/LowPrivilegeEditor), so no CA object could ever produce an ESC5a issue
- gap predates the 55ddc6d refactor; the extraction carried it forward verbatim
- verified: LabRootCA1 now flags Authenticated Users/GenericAll as ESC5a
@jakehildreth
jakehildreth merged commit 886d87d into main Oct 7, 2026
1 check passed
@jakehildreth
jakehildreth deleted the fix/esc5a-ca-editor-detection branch October 7, 2026 02:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant