π’ Certipy Version
5.1.0
π₯οΈ Operating System
Kali GNU/Linux Rolling (2026.3) ARM
π₯ Command Used
certipy-ad relay -target http://DC01.shadow.gate -template DomainController -debug
π§― Error Message / Unexpected Output
(SMB): Authenticating connection from /@10.1.131.88 ...
Generating RSA key
Traceback ...
ValueError: Attribute's length must be >= 1 and <= 64, but it was 0
π Relevant certipy find Output (abbreviated and redacted)
β
Expected Behavior
After receiving a successful relayed NTLM authentication, Certipy should correctly identify the relayed account, generate the CSR, submit the certificate request to the AD CS Web Enrollment endpoint, and save the issued certificate (PFX) when the request succeeds. In the same environment, the relayed authentication succeeds and impacket-ntlmrelayx --adcs --template DomainController successfully retrieves and saves the certificate. I expected certipy-ad relay to behave similarly instead of failing while generating the CSR.
π Additional Context
- Steps to Reproduce
- Start certipy-ad relay ...
- Trigger authentication (e.g., with netexec ... -M coerce_plus).
- Observe successful relay authentication followed by the exception.
- Expected Behavior
- Certipy should parse the relayed identity, generate the CSR, request the certificate, and write the PFX.
- Actual Behavior
- Relay authenticates successfully, but Certipy crashes with: ValueError: Attribute's length must be >= 1 and <= 64, but it was 0
- the log shows
Authenticating connection from /@10.1.131.88

π’ Certipy Version
5.1.0
π₯οΈ Operating System
Kali GNU/Linux Rolling (2026.3) ARM
π₯ Command Used
π§― Error Message / Unexpected Output
π Relevant
certipy findOutput (abbreviated and redacted)β Expected Behavior
After receiving a successful relayed NTLM authentication, Certipy should correctly identify the relayed account, generate the CSR, submit the certificate request to the AD CS Web Enrollment endpoint, and save the issued certificate (PFX) when the request succeeds. In the same environment, the relayed authentication succeeds and impacket-ntlmrelayx --adcs --template DomainController successfully retrieves and saves the certificate. I expected certipy-ad relay to behave similarly instead of failing while generating the CSR.
π Additional Context
Authenticating connection from /@10.1.131.88