Skip to content

fix(find): detect Web Enrollment on HTTP 200/403 responses - #377

Open
alham-rizvi wants to merge 1 commit into
ly4k:mainfrom
alham-rizvi:fix/web-enrollment-200-detection
Open

alham-rizvi wants to merge 1 commit into
ly4k:mainfrom
alham-rizvi:fix/web-enrollment-200-detection

Conversation

@alham-rizvi

Copy link
Copy Markdown

Previously, check_web_enrollment() only treated an HTTP 401 response as evidence that the /certsrv/ endpoint was enabled. Some AD CS configurations return 200 (anonymous browsing permitted, authentication only required for enrollment) or 403, which caused a false negative where Web Enrollment was incorrectly reported as disabled.

  • Treat 403 Forbidden as enabled (service running, access denied).
  • Treat 200 as enabled only when the body looks like the Certificate Services web interface (contains "certsrv" or "certificate services"), to avoid false positives from unrelated web applications.
  • 401 behavior is unchanged.

Fixes #367

Previously, check_web_enrollment() only treated an HTTP 401 response as
evidence that the /certsrv/ endpoint was enabled. Some AD CS
configurations return 200 (anonymous browsing permitted, authentication
only required for enrollment) or 403, which caused a false negative where
Web Enrollment was incorrectly reported as disabled.

- Treat 403 Forbidden as enabled (service running, access denied).
- Treat 200 as enabled only when the body looks like the Certificate
  Services web interface (contains "certsrv" or "certificate services"),
  to avoid false positives from unrelated web applications.
- 401 behavior is unchanged.

Fixes ly4k#367
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] False Negative detection of ADCS Web Enrolment when HTTP 200 is returned instead of 401

1 participant