Repository navigation
fix(detection): populate editor properties on CA objects for ESC5a - #112
Merged
Merged
Conversation
- add Set-DangerousEditor and Set-LowPrivilegeEditor to the CA pipeline in Initialize-AdcsObjectStore - CAs (pKIEnrollmentService) were routed through the CA branch which never ran editor checks, leaving DangerousEditor/LowPrivilegeEditor empty - ESC5a reads EditorProperties (DangerousEditor/LowPrivilegeEditor), so no CA object could ever produce an ESC5a issue - gap predates the 55ddc6d refactor; the extraction carried it forward verbatim - verified: LabRootCA1 now flags Authenticated Users/GenericAll as ESC5a
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
pKIEnrollmentServiceobjects (CAs) could never produce an ESC5a finding. The CA enrichment pipeline inInitialize-AdcsObjectStorenever ranSet-DangerousEditor/Set-LowPrivilegeEditor, soDangerousEditorandLowPrivilegeEditorstayed empty — and ESC5a's definition reads exactly those twoEditorProperties. Result: even a CA withAuthenticated Users / GenericAllon its DACL was invisible to ESC5a.Templates and non-CA infrastructure objects did run the editor checks, which is why ESC5a only ever fired on those (e.g. the AIA object) and never on a CA.
The change
Two enrichment steps added to the CA pipeline in
Private/Initialize/Initialize-AdcsObjectStore.ps1. Carried-forward gap: the pre-refactorInvoke-Locksmith2had the same split;55ddc6dextracted it verbatim.Before / After
Scanned live against
adcs.goat, targetCN=LabRootCA1,CN=Enrollment Services,...,DC=adcs,DC=goat— which hasNT AUTHORITY\Authenticated Users | GenericAll | Allow(direct ACE).[][S-1-5-11]Authenticated Users / GenericAllflaggedAfter: 3 ESC5a issues on LabRootCA1 (
Authenticated Users / GenericAll, plus the CA machine accountADCSGOAT-CA$twice — a separate low-priv-editor finding).Detection gates confirmed sound in isolation:
Test-IsDangerousAcematchesGenericAllforpKIEnrollmentService, andS-1-5-11is a DangerousPrincipal. The ACE itself was always detectable; the object just never got the enrichment.Risk
Low. Additive enrichment to one pipeline branch — no interface changes, no behavior change for templates or other objects. Easily reverted.
Notes
2026.10.61822(CalVer).Set-CADisableExtensionList : Get-PSCDisableExtensionList cmdlet not found(missing optionalPSCertutildependency) — pre-existing, unrelated to this fix, non-fatal to the CA pipeline. Worth a follow-up issue if you want that dependency stubbed or made optional.