Skip to content Book a PKI health check Get incident support
The ESC1 certificate template escalation path A low-privilege user enrols against a certificate template that permits a requester-supplied subject alternative name, carries the client authentication purpose and requires no manager approval. The certificate authority issues a certificate naming a domain administrator, and the user authenticates as that administrator. ESC1 · Requester-supplied SAN Elapsed: minutes Any authenticated user NO PRIVILEGE REQUIRED Vulnerable template ENROLLEE_SUPPLIES_SUBJECT = 1 Certificate issued SAN = ADMINISTRATOR Domain compromise KERBEROS PKINIT CLIENT AUTHENTICATION EKU ENROLL GRANTED TO DOMAIN USERS NO MANAGER APPROVAL

Flagship engagement

The PKI / ADCS Health Check & Security Audit

We assess your CA hierarchy, certificate templates, permissions, revocation infrastructure and key protection against known attack paths and operational failure modes — then hand you a risk-ranked remediation roadmap your engineers can work straight from.

Price
Fixed, $6,000–$12,000 by environment size
Access
Read-only preferred. No changes to production.
Output
Risk-ranked report + remediation walkthrough
Book a PKI health check
Findings extract — 6 of 18 · illustrative Risk 70/100

Who can exploit ESC1?

Elapsed: minutes · The only trace left behind is an issued certificate

Findings shown are representative of a real ADCS assessment. Yours will be your own.

The deliverable

You don’t leave with findings. You leave with a plan.

CoreEncryption PKI security assessment

18 findings

Critical
03
High
04
Medium
06
Low
05
  • Impact, exploitability and a specific fix, per finding
  • Evidence appendix with the raw collection output
  • A verification script for every remediation

Remediation roadmap

Ordered by risk removed per hour of engineering time, not by severity label. The first afternoon takes out more than the following three months.

Three pillars

Specialists, not a generalist security shop.

  • 01 ADCS Services Find dangerous configurations before attackers or outages find them.
  • 02 HSM Services Secure private keys in hardware without breaking the chain of trust.
  • 03 PKI & Encryption Services Prevent certificate outages, modernise trust and prepare the cryptographic estate for what comes next.

How a health check runs

Five steps. Two weeks.
No changes to production.

scoping — call notes
PS> Get-CAHierarchy -Summary

Forest            : corp.example.com
Enterprise CAs    : 3
  ROOT-CA-01      Offline  SHA256  RSA4096  exp 2039
  ISSUING-CA-01   Online   SHA256  RSA2048  exp 2031
  ISSUING-CA-02   Online   SHA1    RSA2048  exp 2029
Published templates : 41
Endpoints (est.)    : 5,000 – 15,000

# scope agreed. no credentials exchanged.

Representative output. Collection scripts are supplied for your review before anything runs.

Priority path

Autoenrolment broken? CRL outage?
Suspected CA compromise?

Describe the symptom, not just the system. The more specific you are, the faster we can tell you whether this is a template issue, a revocation issue, or something worse.

Get incident support Routed separately from routine enquiries.
Response per our stated commitment.

Revocation monitor — ISSUING-CA-01

CRL status
Expired
Next update
overdue 6h 12m
Chain build
Failed

Cache expired · EAP-TLS, VPN and code signing now refusing to validate

event viewer — application
Source:   CertificateServicesClient-AutoEnrollment
Event ID: 13
Level:    Error

Certificate enrollment for Local system failed
to enroll for a Machine certificate with request
ID N/A from corp.example.com\ISSUING-CA-01

  The RPC server is unavailable. 0x800706ba

>> 1,412 machines in 40 minutes
This is what it looks like an hour before anyone calls it an outage.

Why us

Specialist. Vendor-neutral.
Documentation-obsessed.

We do not resell CLM platforms or HSMs, and we do not carry a partner quota. Tooling gets recommended where it is justified and nowhere else. Every engagement leaves you with procedures your own engineers can run.

Chain complete

Certificates shouldn’t be a crisis.

Know what you have. Know where it’s vulnerable.
Know exactly what to fix next.

Book a PKI health check A 30-minute scoping call to confirm whether a health check is the right first move. No credentials exchanged and no obligation.

Already broken? Describe a symptom on the priority path