AD Certificates

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Introduction

Components of a Certificate

  • ์ธ์ฆ์„œ์˜ ์ฃผ์ฒด๋Š” ์†Œ์œ ์ž๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.
  • ๊ณต๊ฐœ ํ‚ค๋Š” ๊ฐœ์ธ ํ‚ค์™€ ์Œ์„ ์ด๋ฃจ์–ด ์ธ์ฆ์„œ๋ฅผ ์ •๋‹นํ•œ ์†Œ์œ ์ž์™€ ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.
  • ์œ ํšจ ๊ธฐ๊ฐ„์€ NotBefore ๋ฐ NotAfter ๋‚ ์งœ๋กœ ์ •์˜๋˜๋ฉฐ, ์ธ์ฆ์„œ์˜ ์œ ํšจ ๊ธฐ๊ฐ„์„ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค.
  • ๊ณ ์œ ํ•œ ์ผ๋ จ ๋ฒˆํ˜ธ๋Š” ์ธ์ฆ ๊ธฐ๊ด€(CA)์—์„œ ์ œ๊ณตํ•˜๋ฉฐ ๊ฐ ์ธ์ฆ์„œ๋ฅผ ์‹๋ณ„ํ•ฉ๋‹ˆ๋‹ค.
  • ๋ฐœ๊ธ‰์ž๋Š” ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•œ CA๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.
  • SubjectAlternativeName์€ ์ฃผ์ฒด์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ์ด๋ฆ„์„ ํ—ˆ์šฉํ•˜์—ฌ ์‹๋ณ„ ์œ ์—ฐ์„ฑ์„ ํ–ฅ์ƒ์‹œํ‚ต๋‹ˆ๋‹ค.
  • ๊ธฐ๋ณธ ์ œ์•ฝ ์กฐ๊ฑด์€ ์ธ์ฆ์„œ๊ฐ€ CA์šฉ์ธ์ง€ ์ตœ์ข… ์—”ํ‹ฐํ‹ฐ์šฉ์ธ์ง€ ์‹๋ณ„ํ•˜๊ณ  ์‚ฌ์šฉ ์ œํ•œ์„ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค.
  • **ํ™•์žฅ ํ‚ค ์‚ฌ์šฉ(EKUs)**์€ ๊ฐ์ฒด ์‹๋ณ„์ž(OIDs)๋ฅผ ํ†ตํ•ด ์ฝ”๋“œ ์„œ๋ช… ๋˜๋Š” ์ด๋ฉ”์ผ ์•”ํ˜ธํ™”์™€ ๊ฐ™์€ ์ธ์ฆ์„œ์˜ ํŠน์ • ๋ชฉ์ ์„ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค.
  • ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜์€ ์ธ์ฆ์„œ ์„œ๋ช… ๋ฐฉ๋ฒ•์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.
  • ์„œ๋ช…์€ ๋ฐœ๊ธ‰์ž์˜ ๊ฐœ์ธ ํ‚ค๋กœ ์ƒ์„ฑ๋˜์–ด ์ธ์ฆ์„œ์˜ ์ง„์œ„๋ฅผ ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค.

Special Considerations

  • **์ฃผ์ฒด ๋Œ€์ฒด ์ด๋ฆ„(SANs)**์€ ์ธ์ฆ์„œ์˜ ์ ์šฉ ๋ฒ”์œ„๋ฅผ ์—ฌ๋Ÿฌ ์‹ ์›์œผ๋กœ ํ™•์žฅํ•˜์—ฌ ์—ฌ๋Ÿฌ ๋„๋ฉ”์ธ์„ ๊ฐ€์ง„ ์„œ๋ฒ„์— ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๊ฐ€ SAN ์‚ฌ์–‘์„ ์กฐ์ž‘ํ•˜์—ฌ ์‚ฌ์นญ ์œ„ํ—˜์„ ํ”ผํ•˜๊ธฐ ์œ„ํ•ด ์•ˆ์ „ํ•œ ๋ฐœ๊ธ‰ ํ”„๋กœ์„ธ์Šค๊ฐ€ ํ•„์ˆ˜์ ์ž…๋‹ˆ๋‹ค.

Certificate Authorities (CAs) in Active Directory (AD)

AD CS๋Š” ์ง€์ •๋œ ์ปจํ…Œ์ด๋„ˆ๋ฅผ ํ†ตํ•ด AD ํฌ๋ฆฌ์ŠคํŠธ์—์„œ CA ์ธ์ฆ์„œ๋ฅผ ์ธ์‹ํ•˜๋ฉฐ, ๊ฐ ์ปจํ…Œ์ด๋„ˆ๋Š” ๊ณ ์œ ํ•œ ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค:

  • ์ธ์ฆ ๊ธฐ๊ด€ ์ปจํ…Œ์ด๋„ˆ๋Š” ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋ฃจํŠธ CA ์ธ์ฆ์„œ๋ฅผ ๋ณด์œ ํ•ฉ๋‹ˆ๋‹ค.
  • ๋“ฑ๋ก ์„œ๋น„์Šค ์ปจํ…Œ์ด๋„ˆ๋Š” ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ CA ๋ฐ ํ•ด๋‹น ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ์ž์„ธํžˆ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.
  • NTAuthCertificates ๊ฐ์ฒด๋Š” AD ์ธ์ฆ์„ ์œ„ํ•ด ์Šน์ธ๋œ CA ์ธ์ฆ์„œ๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.
  • AIA (Authority Information Access) ์ปจํ…Œ์ด๋„ˆ๋Š” ์ค‘๊ฐ„ ๋ฐ ๊ต์ฐจ CA ์ธ์ฆ์„œ์™€ ํ•จ๊ป˜ ์ธ์ฆ์„œ ์ฒด์ธ ์œ ํšจ์„ฑ์„ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.

Certificate Acquisition: Client Certificate Request Flow

  1. ์š”์ฒญ ํ”„๋กœ์„ธ์Šค๋Š” ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ CA๋ฅผ ์ฐพ๋Š” ๊ฒƒ์œผ๋กœ ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค.
  2. ๊ณต๊ฐœ-๊ฐœ์ธ ํ‚ค ์Œ์„ ์ƒ์„ฑํ•œ ํ›„, ๊ณต๊ฐœ ํ‚ค ๋ฐ ๊ธฐํƒ€ ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ํฌํ•จํ•˜๋Š” CSR์ด ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.
  3. CA๋Š” ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์— ๋Œ€ํ•ด CSR์„ ํ‰๊ฐ€ํ•˜๊ณ  ํ…œํ”Œ๋ฆฟ์˜ ๊ถŒํ•œ์— ๋”ฐ๋ผ ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•ฉ๋‹ˆ๋‹ค.
  4. ์Šน์ธ ํ›„, CA๋Š” ๊ฐœ์ธ ํ‚ค๋กœ ์ธ์ฆ์„œ์— ์„œ๋ช…ํ•˜๊ณ  ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค.

Certificate Templates

AD ๋‚ด์—์„œ ์ •์˜๋œ ์ด๋Ÿฌํ•œ ํ…œํ”Œ๋ฆฟ์€ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰์„ ์œ„ํ•œ ์„ค์ • ๋ฐ ๊ถŒํ•œ์„ ๊ฐœ์š”ํ•˜๋ฉฐ, ํ—ˆ์šฉ๋œ EKU ๋ฐ ๋“ฑ๋ก ๋˜๋Š” ์ˆ˜์ • ๊ถŒํ•œ์„ ํฌํ•จํ•˜์—ฌ ์ธ์ฆ์„œ ์„œ๋น„์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค.

Certificate Enrollment

์ธ์ฆ์„œ ๋“ฑ๋ก ํ”„๋กœ์„ธ์Šค๋Š” ๊ด€๋ฆฌ์ž๊ฐ€ ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ์ƒ์„ฑํ•˜๋Š” ๊ฒƒ์œผ๋กœ ์‹œ์ž‘๋˜๋ฉฐ, ์ดํ›„ **์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ์ธ์ฆ ๊ธฐ๊ด€(CA)**์— ์˜ํ•ด ๊ฒŒ์‹œ๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” ํ…œํ”Œ๋ฆฟ์„ ํด๋ผ์ด์–ธํŠธ ๋“ฑ๋ก์„ ์œ„ํ•ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•˜๋ฉฐ, ์ด๋Š” Active Directory ๊ฐ์ฒด์˜ certificatetemplates ํ•„๋“œ์— ํ…œํ”Œ๋ฆฟ ์ด๋ฆ„์„ ์ถ”๊ฐ€ํ•˜์—ฌ ๋‹ฌ์„ฑ๋ฉ๋‹ˆ๋‹ค.

ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญํ•˜๋ ค๋ฉด ๋“ฑ๋ก ๊ถŒํ•œ์ด ๋ถ€์—ฌ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๊ถŒํ•œ์€ ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ ๋ฐ ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ CA ์ž์ฒด์˜ ๋ณด์•ˆ ์„ค๋ช…์ž์— ์˜ํ•ด ์ •์˜๋ฉ๋‹ˆ๋‹ค. ์š”์ฒญ์ด ์„ฑ๊ณตํ•˜๋ ค๋ฉด ๋‘ ์œ„์น˜ ๋ชจ๋‘์—์„œ ๊ถŒํ•œ์ด ๋ถ€์—ฌ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Template Enrollment Rights

์ด๋Ÿฌํ•œ ๊ถŒํ•œ์€ Access Control Entries (ACEs)๋ฅผ ํ†ตํ•ด ์ง€์ •๋˜๋ฉฐ, ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๊ถŒํ•œ์„ ์ž์„ธํžˆ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค:

  • Certificate-Enrollment ๋ฐ Certificate-AutoEnrollment ๊ถŒํ•œ, ๊ฐ๊ฐ ํŠน์ • GUID์™€ ์—ฐ๊ฒฐ๋ฉ๋‹ˆ๋‹ค.
  • ExtendedRights, ๋ชจ๋“  ํ™•์žฅ ๊ถŒํ•œ์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.
  • FullControl/GenericAll, ํ…œํ”Œ๋ฆฟ์— ๋Œ€ํ•œ ์™„์ „ํ•œ ์ œ์–ด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

Enterprise CA Enrollment Rights

CA์˜ ๊ถŒํ•œ์€ ๋ณด์•ˆ ์„ค๋ช…์„œ์— ์š”์•ฝ๋˜์–ด ์žˆ์œผ๋ฉฐ, ์ธ์ฆ ๊ธฐ๊ด€ ๊ด€๋ฆฌ ์ฝ˜์†”์„ ํ†ตํ•ด ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ผ๋ถ€ ์„ค์ •์€ ๋‚ฎ์€ ๊ถŒํ•œ์˜ ์‚ฌ์šฉ์ž์—๊ฒŒ ์›๊ฒฉ ์ ‘๊ทผ์„ ํ—ˆ์šฉํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด๋Š” ๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ์ผ์œผํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Additional Issuance Controls

ํŠน์ • ์ œ์–ด๊ฐ€ ์ ์šฉ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค, ์˜ˆ๋ฅผ ๋“ค์–ด:

  • ๊ด€๋ฆฌ์ž ์Šน์ธ: ์š”์ฒญ์„ ์ธ์ฆ์„œ ๊ด€๋ฆฌ์ž๊ฐ€ ์Šน์ธํ•  ๋•Œ๊นŒ์ง€ ๋ณด๋ฅ˜ ์ƒํƒœ๋กœ ๋‘ก๋‹ˆ๋‹ค.
  • ๋“ฑ๋ก ์—์ด์ „ํŠธ ๋ฐ ์Šน์ธ๋œ ์„œ๋ช…: CSR์— ํ•„์š”ํ•œ ์„œ๋ช…์˜ ์ˆ˜์™€ ํ•„์š”ํ•œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ •์ฑ… OID๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

Methods to Request Certificates

์ธ์ฆ์„œ๋Š” ๋‹ค์Œ์„ ํ†ตํ•ด ์š”์ฒญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  1. Windows Client Certificate Enrollment Protocol (MS-WCCE), DCOM ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
  2. ICertPassage Remote Protocol (MS-ICPR), ๋ช…๋ช…๋œ ํŒŒ์ดํ”„ ๋˜๋Š” TCP/IP๋ฅผ ํ†ตํ•ด.
  3. ์ธ์ฆ์„œ ๋“ฑ๋ก ์›น ์ธํ„ฐํŽ˜์ด์Šค, ์ธ์ฆ ๊ธฐ๊ด€ ์›น ๋“ฑ๋ก ์—ญํ• ์ด ์„ค์น˜๋œ ๊ฒฝ์šฐ.
  4. ์ธ์ฆ์„œ ๋“ฑ๋ก ์„œ๋น„์Šค (CES), ์ธ์ฆ์„œ ๋“ฑ๋ก ์ •์ฑ…(CEP) ์„œ๋น„์Šค์™€ ํ•จ๊ป˜.
  5. ๋„คํŠธ์›Œํฌ ์žฅ์น˜ ๋“ฑ๋ก ์„œ๋น„์Šค (NDES) ๋„คํŠธ์›Œํฌ ์žฅ์น˜๋ฅผ ์œ„ํ•œ, ๊ฐ„๋‹จํ•œ ์ธ์ฆ์„œ ๋“ฑ๋ก ํ”„๋กœํ† ์ฝœ(SCEP)์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

Windows ์‚ฌ์šฉ์ž๋Š” GUI(certmgr.msc ๋˜๋Š” certlm.msc) ๋˜๋Š” ๋ช…๋ น์ค„ ๋„๊ตฌ(certreq.exe ๋˜๋Š” PowerShell์˜ Get-Certificate ๋ช…๋ น)๋ฅผ ํ†ตํ•ด ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

# Example of requesting a certificate using PowerShell
Get-Certificate -Template "User" -CertStoreLocation "cert:\\CurrentUser\\My"

์ธ์ฆ์„œ ์ธ์ฆ

Active Directory (AD)๋Š” ์ธ์ฆ์„œ ์ธ์ฆ์„ ์ง€์›ํ•˜๋ฉฐ, ์ฃผ๋กœ Kerberos ๋ฐ Secure Channel (Schannel) ํ”„๋กœํ† ์ฝœ์„ ํ™œ์šฉํ•ฉ๋‹ˆ๋‹ค.

Kerberos ์ธ์ฆ ํ”„๋กœ์„ธ์Šค

Kerberos ์ธ์ฆ ํ”„๋กœ์„ธ์Šค์—์„œ ์‚ฌ์šฉ์ž์˜ Ticket Granting Ticket (TGT) ์š”์ฒญ์€ ์‚ฌ์šฉ์ž์˜ ์ธ์ฆ์„œ์˜ ๊ฐœ์ธ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ช…๋ฉ๋‹ˆ๋‹ค. ์ด ์š”์ฒญ์€ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์— ์˜ํ•ด ์ธ์ฆ์„œ์˜ ์œ ํšจ์„ฑ, ๊ฒฝ๋กœ, ๋ฐ ํ๊ธฐ ์ƒํƒœ๋ฅผ ํฌํ•จํ•œ ์—ฌ๋Ÿฌ ๊ฒ€์ฆ์„ ๊ฑฐ์นฉ๋‹ˆ๋‹ค. ๊ฒ€์ฆ์—๋Š” ์ธ์ฆ์„œ๊ฐ€ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ถœ์ฒ˜์—์„œ ์™”๋Š”์ง€ ํ™•์ธํ•˜๊ณ  ๋ฐœ๊ธ‰์ž์˜ ์กด์žฌ๋ฅผ NTAUTH ์ธ์ฆ์„œ ์ €์žฅ์†Œ์—์„œ ํ™•์ธํ•˜๋Š” ๊ฒƒ๋„ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ๊ฒ€์ฆ์ด ์„ฑ๊ณต์ ์œผ๋กœ ์™„๋ฃŒ๋˜๋ฉด TGT๊ฐ€ ๋ฐœ๊ธ‰๋ฉ๋‹ˆ๋‹ค. AD์˜ NTAuthCertificates ๊ฐ์ฒด๋Š” ๋‹ค์Œ ์œ„์น˜์— ์žˆ์Šต๋‹ˆ๋‹ค:

CN=NTAuthCertificates,CN=Public Key Services,CN=Services,CN=Configuration,DC=<domain>,DC=<com>

์‹ ๋ขฐ๋ฅผ ๊ตฌ์ถ•ํ•˜๋Š” ๋ฐ ์ค‘์•™ ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.

๋ณด์•ˆ ์ฑ„๋„ (Schannel) ์ธ์ฆ

Schannel์€ ์•ˆ์ „ํ•œ TLS/SSL ์—ฐ๊ฒฐ์„ ์šฉ์ดํ•˜๊ฒŒ ํ•˜๋ฉฐ, ํ•ธ๋“œ์…ฐ์ดํฌ ์ค‘ ํด๋ผ์ด์–ธํŠธ๋Š” ์ธ์ฆ์„œ๋ฅผ ์ œ์‹œํ•˜๊ณ , ์„ฑ๊ณต์ ์œผ๋กœ ๊ฒ€์ฆ๋˜๋ฉด ์ ‘๊ทผ์„ ํ—ˆ๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ์ธ์ฆ์„œ๋ฅผ AD ๊ณ„์ •์— ๋งคํ•‘ํ•˜๋Š” ๊ณผ์ •์€ Kerberos์˜ S4U2Self ๊ธฐ๋Šฅ์ด๋‚˜ ์ธ์ฆ์„œ์˜ ์ฃผ์ฒด ๋Œ€์ฒด ์ด๋ฆ„ (SAN) ๋“ฑ์„ ํฌํ•จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

AD ์ธ์ฆ์„œ ์„œ๋น„์Šค ์—ด๊ฑฐ

AD์˜ ์ธ์ฆ์„œ ์„œ๋น„์Šค๋Š” LDAP ์ฟผ๋ฆฌ๋ฅผ ํ†ตํ•ด ์—ด๊ฑฐํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ์ธ์ฆ ๊ธฐ๊ด€ (CAs) ๋ฐ ๊ทธ ๊ตฌ์„ฑ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋“œ๋Ÿฌ๋ƒ…๋‹ˆ๋‹ค. ์ด๋Š” ํŠน๋ณ„ํ•œ ๊ถŒํ•œ ์—†์ด ๋„๋ฉ”์ธ ์ธ์ฆ๋œ ์‚ฌ์šฉ์ž๋ผ๋ฉด ๋ˆ„๊ตฌ๋‚˜ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Certify ๋ฐ **Certipy**์™€ ๊ฐ™์€ ๋„๊ตฌ๋Š” AD CS ํ™˜๊ฒฝ์—์„œ ์—ด๊ฑฐ ๋ฐ ์ทจ์•ฝ์„ฑ ํ‰๊ฐ€์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

์ด ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ช…๋ น์–ด๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:

# Enumerate trusted root CA certificates and Enterprise CAs with Certify
Certify.exe cas
# Identify vulnerable certificate templates with Certify
Certify.exe find /vulnerable

# Use Certipy (>=4.0) for enumeration and identifying vulnerable templates
certipy find -vulnerable -dc-only -u john@corp.local -p Passw0rd -target dc.corp.local

# Request a certificate over the web enrollment interface (new in Certipy 4.x)
certipy req -web -target ca.corp.local -template WebServer -upn john@corp.local -dns www.corp.local

# Enumerate Enterprise CAs and certificate templates with certutil
certutil.exe -TCAInfo
certutil -v -dstemplate

์ตœ๊ทผ ์ทจ์•ฝ์  ๋ฐ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ (2022-2025)

์—ฐ๋„ID / ์ด๋ฆ„์˜ํ–ฅ์ฃผ์š” ์‚ฌํ•ญ
2022CVE-2022-26923 โ€“ โ€œCertifriedโ€ / ESC6๊ถŒํ•œ ์ƒ์Šน์„ ์œ„ํ•œ ๊ธฐ๊ณ„ ๊ณ„์ • ์ธ์ฆ์„œ ์Šคํ‘ธํ•‘.2022๋…„ 5์›” 10์ผ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ์— ํŒจ์น˜ ํฌํ•จ. ๊ฐ์‚ฌ ๋ฐ ๊ฐ•๋ ฅํ•œ ๋งคํ•‘ ์ œ์–ด๊ฐ€ KB5014754๋ฅผ ํ†ตํ•ด ๋„์ž…๋จ; ํ™˜๊ฒฝ์€ ์ด์ œ ์ „์ฒด ์‹œํ–‰ ๋ชจ๋“œ์—ฌ์•ผ ํ•จ.
2023CVE-2023-35350 / 35351์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์ด AD CS ์›น ๋“ฑ๋ก(certsrv) ๋ฐ CES ์—ญํ• ์—์„œ ๋ฐœ์ƒ.๊ณต๊ฐœ PoC๋Š” ์ œํ•œ์ ์ด์ง€๋งŒ, ์ทจ์•ฝํ•œ IIS ๊ตฌ์„ฑ ์š”์†Œ๋Š” ์ข…์ข… ๋‚ด๋ถ€์— ๋…ธ์ถœ๋จ. 2023๋…„ 7์›” ํŒจ์น˜ ํ™”์š”์ผ ๊ธฐ์ค€ ํŒจ์น˜.
2024CVE-2024-49019 โ€“ โ€œEKUwuโ€ / ESC15๋“ฑ๋ก ๊ถŒํ•œ์ด ์žˆ๋Š” ์ €๊ถŒํ•œ ์‚ฌ์šฉ์ž๊ฐ€ CSR ์ƒ์„ฑ ์ค‘ ๋ชจ๋“  EKU ๋˜๋Š” SAN์„ ์žฌ์ •์˜ํ•  ์ˆ˜ ์žˆ์–ด ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ ๋˜๋Š” ์ฝ”๋“œ ์„œ๋ช…์— ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•˜๊ณ  ๋„๋ฉ”์ธ ์†์ƒ์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Œ.2024๋…„ 4์›” ์—…๋ฐ์ดํŠธ์—์„œ ํ•ด๊ฒฐ๋จ. ํ…œํ”Œ๋ฆฟ์—์„œ โ€œ์š”์ฒญ์— ๊ณต๊ธ‰โ€์„ ์ œ๊ฑฐํ•˜๊ณ  ๋“ฑ๋ก ๊ถŒํ•œ์„ ์ œํ•œํ•  ๊ฒƒ.

Microsoft ๊ฐ•ํ™” ์ผ์ • (KB5014754)

Microsoft๋Š” Kerberos ์ธ์ฆ์„œ๋ฅผ ์•ฝํ•œ ์•”์‹œ์  ๋งคํ•‘์—์„œ ๋ฒ—์–ด๋‚˜๊ธฐ ์œ„ํ•ด ์„ธ ๋‹จ๊ณ„ ๋กค์•„์›ƒ(ํ˜ธํ™˜์„ฑ โ†’ ๊ฐ์‚ฌ โ†’ ์‹œํ–‰)์„ ๋„์ž…ํ–ˆ์Šต๋‹ˆ๋‹ค. 2025๋…„ 2์›” 11์ผ ๊ธฐ์ค€์œผ๋กœ, ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ๋Š” StrongCertificateBindingEnforcement ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๊ฐ’์ด ์„ค์ •๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ์ž๋™์œผ๋กœ ์ „์ฒด ์‹œํ–‰์œผ๋กœ ์ „ํ™˜๋ฉ๋‹ˆ๋‹ค. ๊ด€๋ฆฌ์ž๋Š” ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค:

  1. ๋ชจ๋“  DC ๋ฐ AD CS ์„œ๋ฒ„๋ฅผ ํŒจ์น˜ํ•ฉ๋‹ˆ๋‹ค(2022๋…„ 5์›” ๋˜๋Š” ์ดํ›„).
  2. ๊ฐ์‚ฌ ๋‹จ๊ณ„์—์„œ ์•ฝํ•œ ๋งคํ•‘์— ๋Œ€ํ•ด ์ด๋ฒคํŠธ ID 39/41์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•ฉ๋‹ˆ๋‹ค.
  3. 2025๋…„ 2์›” ์ด์ „์— ์ƒˆ๋กœ์šด SID ํ™•์žฅ์œผ๋กœ ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ์„œ๋ฅผ ์žฌ๋ฐœ๊ธ‰ํ•˜๊ฑฐ๋‚˜ ๊ฐ•๋ ฅํ•œ ์ˆ˜๋™ ๋งคํ•‘์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

ํƒ์ง€ ๋ฐ ๊ฐ•ํ™” ๊ฐœ์„  ์‚ฌํ•ญ

  • **Defender for Identity AD CS ์„ผ์„œ (2023-2024)**๋Š” ์ด์ œ ESC1-ESC8/ESC11์— ๋Œ€ํ•œ ์ž์„ธํ•œ ํ‰๊ฐ€๋ฅผ ์ œ๊ณตํ•˜๊ณ  โ€œ๋น„ DC์— ๋Œ€ํ•œ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰โ€ (ESC8) ๋ฐ โ€œ์ž„์˜์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ •์ฑ…์œผ๋กœ ์ธ์ฆ์„œ ๋“ฑ๋ก ๋ฐฉ์ง€โ€ (ESC15)์™€ ๊ฐ™์€ ์‹ค์‹œ๊ฐ„ ๊ฒฝ๊ณ ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํƒ์ง€๋ฅผ ํ™œ์šฉํ•˜๊ธฐ ์œ„ํ•ด ๋ชจ๋“  AD CS ์„œ๋ฒ„์— ์„ผ์„œ๋ฅผ ๋ฐฐํฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ๋ชจ๋“  ํ…œํ”Œ๋ฆฟ์—์„œ โ€œ์š”์ฒญ์— ๊ณต๊ธ‰โ€ ์˜ต์…˜์„ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ฑฐ๋‚˜ ์—„๊ฒฉํ•˜๊ฒŒ ๋ฒ”์œ„๋ฅผ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค; ๋ช…์‹œ์ ์œผ๋กœ ์ •์˜๋œ SAN/EKU ๊ฐ’์„ ์„ ํ˜ธํ•ฉ๋‹ˆ๋‹ค.
  • ํ…œํ”Œ๋ฆฟ์—์„œ Any Purpose ๋˜๋Š” No EKU๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค(์ ˆ๋Œ€ ํ•„์š”ํ•œ ๊ฒฝ์šฐ ์ œ์™ธ, ESC2 ์‹œ๋‚˜๋ฆฌ์˜ค ํ•ด๊ฒฐ).
  • ๋ฏผ๊ฐํ•œ ํ…œํ”Œ๋ฆฟ(์˜ˆ: WebServer / CodeSigning)์— ๋Œ€ํ•ด ๊ด€๋ฆฌ์ž ์Šน์ธ ๋˜๋Š” ์ „์šฉ ๋“ฑ๋ก ์—์ด์ „ํŠธ ์›Œํฌํ”Œ๋กœ๋ฅผ ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค.
  • ์›น ๋“ฑ๋ก(certsrv) ๋ฐ CES/NDES ์—”๋“œํฌ์ธํŠธ๋ฅผ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋„คํŠธ์›Œํฌ๋กœ ์ œํ•œํ•˜๊ฑฐ๋‚˜ ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ์„œ ์ธ์ฆ ๋’ค์— ๋ฐฐ์น˜ํ•ฉ๋‹ˆ๋‹ค.
  • ESC11์„ ์™„ํ™”ํ•˜๊ธฐ ์œ„ํ•ด RPC ๋“ฑ๋ก ์•”ํ˜ธํ™”(certutil โ€“setreg CA\InterfaceFlags +IF_ENFORCEENCRYPTICERTREQ)๋ฅผ ์‹œํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์ฐธ๊ณ  ๋ฌธํ—Œ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ