Skip to content

Conversation

@fbogner
Copy link

@fbogner fbogner commented Jun 6, 2024

During a recent penetration test we discovered that the customer had given end user's the permission to read the private keys of several certificates within the computer store. As some could be used for authentication we tried to use /asktgt on them. However, because only the user's store is searched in the current release this failed.

Hence, we updated the sourcecode to not only check the user's, but also the computer store.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant