Skip to content

[Bug] relay: Empty relayed username causes create_csr() to fail with ValueError: Attribute's length must be >= 1Β #372

Description

@I-AlanF90

πŸ”’ Certipy Version

5.1.0

πŸ–₯️ Operating System

Kali GNU/Linux Rolling (2026.3) ARM

πŸ“₯ Command Used

certipy-ad relay -target http://DC01.shadow.gate -template DomainController -debug

🧯 Error Message / Unexpected Output

(SMB): Authenticating connection from /@10.1.131.88 ...
Generating RSA key
Traceback ...
ValueError: Attribute's length must be >= 1 and <= 64, but it was 0

πŸ” Relevant certipy find Output (abbreviated and redacted)


βœ… Expected Behavior

After receiving a successful relayed NTLM authentication, Certipy should correctly identify the relayed account, generate the CSR, submit the certificate request to the AD CS Web Enrollment endpoint, and save the issued certificate (PFX) when the request succeeds. In the same environment, the relayed authentication succeeds and impacket-ntlmrelayx --adcs --template DomainController successfully retrieves and saves the certificate. I expected certipy-ad relay to behave similarly instead of failing while generating the CSR.

πŸ“Ž Additional Context

  • Steps to Reproduce
    1. Start certipy-ad relay ...
    2. Trigger authentication (e.g., with netexec ... -M coerce_plus).
    3. Observe successful relay authentication followed by the exception.
  • Expected Behavior
    • Certipy should parse the relayed identity, generate the CSR, request the certificate, and write the PFX.
  • Actual Behavior
    • Relay authenticates successfully, but Certipy crashes with: ValueError: Attribute's length must be >= 1 and <= 64, but it was 0
    • the log shows
      Authenticating connection from /@10.1.131.88
Image Image Image

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions