You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If an attacker uses petitpotam and cooerces the machine account to try to log into the relay, we should try and identify that specific login and instead of using the standard machine template, we should issue the DC template.
There are a few ways we can do this- we could try and issue the cert with the DC template and then fall back to the machine template if we fail, or possibly, we just need to check to see if we have access to the DC template, and then issue the cert only if we have access to the template.
The text was updated successfully, but these errors were encountered:
If an attacker uses petitpotam and cooerces the machine account to try to log into the relay, we should try and identify that specific login and instead of using the standard machine template, we should issue the DC template.
There are a few ways we can do this- we could try and issue the cert with the DC template and then fall back to the machine template if we fail, or possibly, we just need to check to see if we have access to the DC template, and then issue the cert only if we have access to the template.
The text was updated successfully, but these errors were encountered: