Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Increase points for "Check if authentication certificate templates allow users to control the subject" ? #220

Open
ruppde opened this issue Mar 7, 2024 · 1 comment

Comments

@ruppde
Copy link
Contributor

ruppde commented Mar 7, 2024

The check for "Check if authentication certificate templates allow users to control the subject" is valued with just 15 points, but might result in a straight domain takeover from any normal user using certipy/certify. Compared to many other checks, I would give that more points, e.g. 50.

@ruppde
Copy link
Contributor Author

ruppde commented May 9, 2024

Another check which should give more points is missing signing as that also helps mitigate all those coercion + relay attacks. The text mostly mentions MITM attacks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant