Skip to content

Pr code - #376

Closed
sheepiroth1 wants to merge 2 commits into
ly4k:mainfrom
sheepiroth1:pr-code
Closed

sheepiroth1 wants to merge 2 commits into
ly4k:mainfrom
sheepiroth1:pr-code

Conversation

@sheepiroth1

Copy link
Copy Markdown

No description provided.

Robert Cooper and others added 2 commits August 19, 2026 10:30
Some AD CS certificate templates require ECDSA_P256 (or ECDH_P256/P384/P521)
private keys via the msPKI-RA-Application-Policies attribute. Previously,
Certipy generated RSA keys unconditionally and the CA rejected such requests
with CERTSRV_E_BAD_REQUESTSTATUS (0x80094003).

This adds:
- generate_ec_key(curve_name) - creates an EC private key on the requested
  NIST curve (P256, P384, or P521).
- sign_csr_data(...) - key-type-aware CSR signer (RSA-PKCS1v1.5 or ECDSA).
- Two new CLI arguments on certipy req:
    -key-type {rsa,ec,ecdsa,ecdh}   default: rsa
    -curve {P256,P384,P521}         default: P256
- The CSR signature_algorithm OID is now selected based on the key type
  (sha256_ecdsa for EC keys, sha256_rsa for RSA keys).

certipy auth (PKINIT) is not yet updated to consume EC private keys;
-ldap-shell is a working post-issuance alternative. A follow-up PR can
extend PKINIT if there is interest.
@sheepiroth1
sheepiroth1 deleted the pr-code branch September 25, 2026 05:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant