Skip to content

AD CS Overview

Active Directory Certificate Services (AD CS) is a critical component of Microsoft Active Directory that enables the issuance and management of digital certificates. These certificates are used to secure communication, authenticate services, and enforce encryption policies within an AD environment. At its core, AD CS relies on Certificate Authorities (CAs) to validate identities, issue certificates, and manage their lifecycle. Understanding how AD CS operates is foundational for analyzing and exploiting certificate-based vulnerabilities, such as those involving Kerberos delegation or certificate impersonation.


Certificate Authorities (CAs) in AD CS

AD CS supports two primary types of CAs:
1. Enterprise CAs: Integrated with Active Directory, these CAs use AD DS (Directory Services) to store certificate databases and manage trust relationships. They are typically used in enterprise environments.
2. Standalone CAs: Not integrated with AD DS, these operate independently and are often used for smaller or non-AD environments.

CAs in AD CS are responsible for:
- Validating certificate enrollment requests.
- Issuing certificates based on predefined templates.
- Revoking certificates via Certificate Revocation Lists (CRLs) or Online Certificate Status Protocol (OCSP).

Example: To check the status of a CA in AD CS, use the certutil tool:

certutil -viewstore -ca


Certificate Enrollment Process

The certificate enrollment workflow involves three stages:
1. Request Submission: A user or service submits a certificate request (e.g., via certreq or the CA Web Enrollment interface).
2. Approval: The CA validates the request against policies (e.g., certificate templates, permissions).
3. Issuance: The CA generates the certificate, signs it with its private key, and returns it to the requester.

Example: Enroll a certificate using certreq (simplified):

certreq -submit -config "MyCA" -attrib "CertificateTemplate=WebServer" certificate_request.req


Certificate Stores and Private Key Management

AD CS certificates are stored in Windows certificate stores, such as:
- Local Machine (for system services).
- Current User (for user-specific certificates).

Private keys are protected by the Key Storage Provider (KSP), which ensures they are encrypted and accessible only to authorized entities.

Example: View certificates in the "My" store:

certutil -viewstore -user My


Certification Authority Web Enrollment

The CA Web Enrollment feature allows automated certificate enrollment via HTTP/HTTPS. It is commonly used for services like Kerberos delegation or secure client-server communication.

Example: Enroll a certificate using the CA Web Enrollment interface:
1. Navigate to https://<CA_FQDN>/certsrv in a browser.
2. Select "Enroll" and follow the wizard to submit a request.


Key takeaways

  • AD CS relies on CAs to issue, manage, and revoke certificates, ensuring secure communication and authentication.
  • Enterprise CAs integrate with AD DS, while Standalone CAs operate independently.
  • Certificate enrollment involves validation, approval, and issuance stages.
  • Private keys are protected by KSP, and certificates are stored in Windows certificate stores.
  • Web Enrollment enables automated certificate requests for services like Kerberos.