Skip to content

Search certificates in User and Computer store#190

Open
fbogner wants to merge 1 commit intoGhostPack:masterfrom
fbogner:master
Open

Search certificates in User and Computer store#190
fbogner wants to merge 1 commit intoGhostPack:masterfrom
fbogner:master

Conversation

@fbogner
Copy link
Copy Markdown

@fbogner fbogner commented Jun 6, 2024

During a recent penetration test we discovered that the customer had given end user's the permission to read the private keys of several certificates within the computer store. As some could be used for authentication we tried to use /asktgt on them. However, because only the user's store is searched in the current release this failed.

Hence, we updated the sourcecode to not only check the user's, but also the computer store.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant