CTD-000158

The certificate template has a key length of less than 2048 bits

High
Active Directory Certificate Services (ADCS)
Privilege Escalation
v17

Signature Identity

CTD-000158
Threat ID
17
Version
IOE
Indicator Type

Threat Description

A threat actor can exploit weak or vulnerable certificates by exploiting several inherent weaknesses, particularly random number generation, key size, and susceptibility to side-channel attacks. Replacing vulnerable keys with more modern and secure cryptographic algorithms mitigates these risks. To secure your environment, it’s essential to phase out secure certificates, revoke any currently issued weak certificates, and replace them with certificates using stronger algorithms and key sizes.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Credential Hardening

Remediation

  1. To open the Certificate Templetes console:
    1. Press Win + R.
    2. Type certtmpl.msc.
    3. Press Enter.
  2. Right-click the existing template.
  3. Select Duplicate Template.
  4. Choose Windows Server 2008 or later.
  5. Click OK.
  6. In the Properties of the new template, navigate to the Cryptography tab.
  7. Set Minimum Key Size to 2048 or higher.
  8. Update other settings as needed.
  9. Click OK.
  10. To publish the templeate, open the Certification Authority Console (certsrv.msc).
  11. Right-click Certificate Templates.
  12. Select New > Certificate Template to Issue.
  13. Choose the new template.
  14. Retire the old template if no longer needed.

Frequently Asked Questions

What does The certificate template has a key length of less than 2048 bits mean?

The certificate template has a key length of less than 2048 bits indicates that the default cryptographic settings for certificates in the Active Directory environment Certificate Services (ADCS) environment are not secure. Specifically, the key length of the certificates generated by this template is less than 2048 bits, making them susceptible to certain types of attacks.

The certificate template has a key length of less than 2048 bits is rated high severity because it allows attackers to exploit weaknesses in random number generation and side-channel attacks, compromising the confidentiality and integrity of sensitive data.

Attackers can use the weak certificates generated by this template to perform brute-force attacks or side-channel attacks, which can compromise the confidentiality and integrity of sensitive data.

Cayosoft Guardian detects The certificate template has a key length of less than 2048 bits by continuously monitoring the cryptographic settings and certificate templates in your ADCS environment, identifying any certificate templates with a key length of less than 2048 bits.

Cayosoft Guardian helps reduce the risk by alerting administrators to take corrective action, such as updating the cryptographic settings and replacing weak certificates with more secure ones, providing visibility into potential attack paths and supporting investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory Certificate Services (ADCS)
Themes
Infrastructure
Attack Tactics
Privilege Escalation
Defend Tactics
Credential Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical