Minding the Keystore
Minding the Keystore
  • 98
  • 15 596
Event Log Filtering
👉SUBSCRIBE
Be sure to Subscribe and click that Bell Icon for notifications!
Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight!
pkispotlight.com/
///FREE TRAINING\\\
Try our online PKI in-Depth Training Course for free here:
www.pkisolutions.com/training/#online
///FOLLOW US ON SOCIAL\\\
LINKEDIN: www.linkedin.com/company/pki-solutions/
TWITTER: pkisolutions
BLOG: www.pkisolutions.com/thepkiblog/
#mindingthekeystore​​ #pki​​ #adcs #microsoft #pki spotlight
///DISCLAIMER\\\
Some of the links posted here may be affiliate links. This means if you use these links and purchase, we may earn a small commission. Any funds from affiliate links help support the cost of the channel. We will only share links to products we use and approve of, or other PKI professionals who we trust have tried those products and endorse.
มุมมอง: 29

วีดีโอ

PKI Maturity Assessment
มุมมอง 4914 วันที่ผ่านมา
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING\\\ Try our online PKI in-Depth Training Course for free here: www.pkisolutions.com/training/#online ///FOLLOW US ON SOCIAL\\\ LINKEDIN: www.linkedin.com/company/pki-solutions/ TWITTER: twitt...
Expiring Certificates and CRLs
มุมมอง 5414 วันที่ผ่านมา
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING PREVIEW\\\ Try our online PKI in-depth Training Course for free here: platform.pkisolutions.com/shop/self-paced-microsoft-pki-in-depth-online-training-free-trial/ ///FOLLOW US ON SOCIAL\\\ L...
PKI Insights - September 2024 - Post-Quantum (PQC) Cryptography and PKI
มุมมอง 12521 วันที่ผ่านมา
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE ADCS ASSESSMENT\\\\ Learn about how our reporting tools can be used to give detailed reporting metrics for your Active Directory Certificate Services/PKI here: www.pkisolutions.com/assessments/ and t...
PKI Insights - July 2024 - Past, Present, and Future of PKI with Brian Komar
มุมมอง 3432 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE ADCS ASSESSMENT\\\\ Learn about how our reporting tools can be used to give detailed reporting metrics for your Active Directory Certificate Services/PKI here: www.pkisolutions.com/assessments/ and t...
PKI Insights - May 2024 - PKI Posture Management with PKI Spotlight
มุมมอง 1064 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE ADCS ASSESSMENT\\\\ Learn about how our reporting tools can be used to give detailed reporting metrics for your Active Directory Certificate Services/PKI here: www.pkisolutions.com/assessments/ and t...
PKI Insights - April 2024 - PKI Posture Management for Digital Certificates
มุมมอง 1365 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE ADCS ASSESSMENT\\\ Learn about how our reporting tools can be used to give detailed reporting metrics for your Active Directory Certificate Services/PKI here: www.pkisolutions.com/assessments/ and th...
Detection of High-Value Certificates
มุมมอง 636 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING PREVIEW\\\ Try our online PKI in-depth Training Course for free here: platform.pkisolutions.com/shop/self-paced-microsoft-pki-in-depth-online-training-free-trial/ ///FOLLOW US ON SOCIAL\\\ L...
PKI Insight March '24 Energy Utility PKI Cybersecurity in Critical Infrastructure (CIP) Environments
มุมมอง 666 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING\\\ Try our online PKI In-Depth Training Course for free here: www.pkisolutions.com/training/#online ///FOLLOW US ON SOCIAL\\\ LINKEDIN: www.linkedin.com/company/pki-solutions/ TWITTER: twitt...
PKI Insights - February 2024 Avoiding PenTest Pitfalls
มุมมอง 1907 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING\\\ Try our online PKI In-Depth Training Course for free here: www.pkisolutions.com/training/#online ///FOLLOW US ON SOCIAL\\\ LINKEDIN: www.linkedin.com/company/pki-solutions/ TWITTER: twitt...
The Secrets to Secrets Management
มุมมอง 828 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING\\\ Try our online PKI In-Depth Training Course for free here: www.pkisolutions.com/training/#online ///FOLLOW US ON SOCIAL\\\ LINKEDIN: www.linkedin.com/company/pki-solutions/ TWITTER: twitt...
PKI Solutions PKI Insight (January 2024) - Microsoft Intune Cloud PKI
มุมมอง 7449 หลายเดือนก่อน
In this webinar, Mark B. Cooper- The PKI Guy, unravels the complexities and potentials of the recently announced Microsoft Intune Cloud PKI, a cloud-based system that integrates with Microsoft Intune for the issuance of client certificates for Windows, iOS, macOS, and Android. Join us as we explore the pros and cons of the new solution offering and how it aligns with industry standards and the ...
PKI Spotlight Data Extracts
มุมมอง 379 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING PREVIEW\\\ Try our online PKI in-depth Training Course for free here: platform.pkisolutions.com/shop/self-paced-microsoft-pki-in-depth-online-training-free-trial/ ///FOLLOW US ON SOCIAL\\\ L...
PKI Spotlight Offline Data Collector
มุมมอง 539 หลายเดือนก่อน
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING PREVIEW\\\ Try our online PKI in-depth Training Course for free here: platform.pkisolutions.com/shop/self-paced-microsoft-pki-in-depth-online-training-free-trial/ ///FOLLOW US ON SOCIAL\\\ L...
PKI Spotlight Health Alerts
มุมมอง 61ปีที่แล้ว
👉SUBSCRIBE Be sure to Subscribe and click that Bell Icon for notifications! Need help monitoring your certificate authorities and related servers? Check out PKI Spotlight! pkispotlight.com/ ///FREE TRAINING PREVIEW\\\ Try our online PKI in-depth Training Course for free here: platform.pkisolutions.com/shop/self-paced-microsoft-pki-in-depth-online-training-free-trial/ ///FOLLOW US ON SOCIAL\\\ L...
PKI Spotlight Email Digest
มุมมอง 38ปีที่แล้ว
PKI Spotlight Email Digest
PKI Spotlight Co-Management
มุมมอง 47ปีที่แล้ว
PKI Spotlight Co-Management
PKI Spotlight Is-Alive
มุมมอง 94ปีที่แล้ว
PKI Spotlight Is-Alive
High Value Cert Detection
มุมมอง 43ปีที่แล้ว
High Value Cert Detection
Unknown OSCP Responder Detection
มุมมอง 51ปีที่แล้ว
Unknown OSCP Responder Detection
SIEM - Splunk Integration
มุมมอง 30ปีที่แล้ว
SIEM - Splunk Integration
SpecterOps - Threat Detection
มุมมอง 74ปีที่แล้ว
SpecterOps - Threat Detection
PKI Spotlight: Strengthening Your Security Through Automated Threat Detection
มุมมอง 58ปีที่แล้ว
PKI Spotlight: Strengthening Your Security Through Automated Threat Detection
Deadlines, Impact & Action: Certificate Based Authentication Changes (KB5014754)
มุมมอง 942ปีที่แล้ว
Deadlines, Impact & Action: Certificate Based Authentication Changes (KB5014754)
February 7, 2023 PKI Spotlight Release with PetitPotam and Kerberos CA Escalation Demos
มุมมอง 102ปีที่แล้ว
February 7, 2023 PKI Spotlight Release with PetitPotam and Kerberos CA Escalation Demos
PKI Spotlight | Prevent Malicious Users from exploiting ADCS certificates and take full control
มุมมอง 200ปีที่แล้ว
PKI Spotlight | Prevent Malicious Users from exploiting ADCS certificates and take full control
PKI Spotlight | Real-Time Detection of PetitPotam (CVE-2021-36942) Vulnerability
มุมมอง 230ปีที่แล้ว
PKI Spotlight | Real-Time Detection of PetitPotam (CVE-2021-36942) Vulnerability
Threat Modeling | Keys Certificate and PKIS - The Basics
มุมมอง 90ปีที่แล้ว
Threat Modeling | Keys Certificate and PKIS - The Basics
PKI Spotlight | Threat Analysis for Malicious Code Signing
มุมมอง 17ปีที่แล้ว
PKI Spotlight | Threat Analysis for Malicious Code Signing
PKI Threat Analysis | Malicious Code Signing
มุมมอง 114ปีที่แล้ว
PKI Threat Analysis | Malicious Code Signing

ความคิดเห็น

  • @faridrezal3418
    @faridrezal3418 3 วันที่ผ่านมา

    I really enjoyed watching this video, thanks for sharing.

  • @Korn45678
    @Korn45678 14 วันที่ผ่านมา

    Awesome!!

  • @HestnetIT
    @HestnetIT 25 วันที่ผ่านมา

    Great discussion. Thanks for sharing your knowledge and experiences Brian. I hope to see the new book someday. Enjoy your retirement!

  • @rajugavandi7036
    @rajugavandi7036 หลายเดือนก่อน

    Great, Presentation . I have implemented my company PKI in 2013.

  • @Korn45678
    @Korn45678 หลายเดือนก่อน

    Awesome!

  • @johnhoarfrost4524
    @johnhoarfrost4524 5 หลายเดือนก่อน

    Great content! Would love a post launch follow up video re-exploring MS Cloud PKI.

  • @gabrielalexanderclothingco8156
    @gabrielalexanderclothingco8156 8 หลายเดือนก่อน

    What would be the process or command to renew the root ca cert from a windows core server?

  • @Jamesaepp
    @Jamesaepp 8 หลายเดือนก่อน

    Interesting video. One thing I'm surprised he didn't touch on during the discussion about HTTP vs LDAP CRL publication is about how when using LDAP, the CA role service by default assumes a lot of things about the path it should use. That's great until you have to change anything, such as rebuild your CA or go through a naming scheme restructure (domain or server name). I prefer to use HTTP for CRLs - it forces you to pick a (hopefully static) FQDN and pattern to publish your CRLs too which will work long-term. LDAP is fine for some use cases, but I like using HTTP.

  • @GCASTest
    @GCASTest 9 หลายเดือนก่อน

    It's interesting why you compare Intune PKI only with NDES used for Intune which is required to be exposed to the internet and not the PFX connector which eliminates this requirement, very simple to implement and secure (knowing the keys are generated on the PFX connector and not on the device) .

  • @50PullUps
    @50PullUps ปีที่แล้ว

    Thanks for recording this. You brought clarity to quite a few concepts that I only dimmly understood.

  • @50PullUps
    @50PullUps ปีที่แล้ว

    Hyper-V is AWESOME.

  • @JohnC-dm7jm
    @JohnC-dm7jm ปีที่แล้ว

    The main idea is that you should replace all authentication certificates with new OID till November 14. Don't understand why April 11 is mentioned as deadline. April 11 affects only certificates which predates accounts, which should be very rare case. Of course it is better not wait for November 14 and migrate to full enforcement as fast as possible, but real deadline is November 14.

  • @deenoc3622
    @deenoc3622 ปีที่แล้ว

    The fallout of the Absuing Active Directory Certificate Services whitepaper still continues to amaze.

  • @emeryhazlehurst932
    @emeryhazlehurst932 ปีที่แล้ว

    😩 "promosm".

  • @Rasos
    @Rasos ปีที่แล้ว

    Thanks for posting this. Very good info

  • @WayneHarris
    @WayneHarris ปีที่แล้ว

    I know you qualified your statement about not needing to revoke, but I thought I would chime in here. A lot of Certificate Policies that I have written, and others that I have read, mandate that end-entity certificates need to be revoke-able over their lifespan. Extending the lifespan of the CRL to match the expiration of a CA effectively removes that capability, and would place my former customers in violation of their own certificate policies. For that reason, I always push back on the very common request to "extend the lifespan" of a given CRL. Just my .02cents. Love these videos BTW.

  • @HazemElsaiegh1
    @HazemElsaiegh1 ปีที่แล้ว

    excellent tip

  • @LionRelaxe
    @LionRelaxe 2 ปีที่แล้ว

    I am new to the PKI stuff, and I was watching you other videos. Then I found this, wow. I have not been required to "pre-test" my AD stuff, as most of the things are easy to setup and/or correct (think GPOs). But this automated lab is a game changer for PKI education. You note the documentation is really great, but your video actually helped me trough a couple of blind spots. Thanks you!

  • @Vaniteez
    @Vaniteez 2 ปีที่แล้ว

    Great video and voice over

  • @kingdwight1
    @kingdwight1 2 ปีที่แล้ว

    Can you also script sub-OUs? In the videos I only see one level OUs.

    • @MindingtheKeystore
      @MindingtheKeystore 2 ปีที่แล้ว

      The AD-OU json file creates top level OUs. If you wanted to create sub OUs, you could use PowerShell to create more sub OUs, post lab deployment.

  • @kingdwight1
    @kingdwight1 2 ปีที่แล้ว

    Great video!!! Question... What happens with the lab after 90 days? Do we have to go thru the process of scrapping and restarting a new environment?

    • @MindingtheKeystore
      @MindingtheKeystore 2 ปีที่แล้ว

      Microsoft Trial software is good for 180 days, then you would have to rebuild.

  • @HopliteSecurity
    @HopliteSecurity 2 ปีที่แล้ว

    This was a great video! Thank you David and keep up the amazing work!

  • @WayneHarris
    @WayneHarris 2 ปีที่แล้ว

    This software is underrated. 100% of the clients I know, could benefit from this software, and the practices it seeks to automate. Nice job.

  • @Mr_Sh1tcoin
    @Mr_Sh1tcoin 2 ปีที่แล้ว

    This is a great ps module, thank you guys. I have utilised this today in a script with a few logic gates to ultimately spit an email out to the ticket system if a cert is expiring within 30 days. It will only do it once based on a txt file which it outputs on first time a cert expires, as subsequent runs of the script polls the directory for the text file of the cert; txt file present = don't send another email. All txt files are purged after last write time older than 30 days, therefore next year's expiry will get picked up. Be happy to show you guys if you're interested!

    • @Mr_Sh1tcoin
      @Mr_Sh1tcoin 2 ปีที่แล้ว

      I also have used similar logic in another script which polls public URLs which use 3rd party issued certificates and report expiring certificates. It breaks out .NET connection and TLS handshake to query the certificate details. Granted most 3rd party CAs have notifications of certificate renewals required, this is a good fail safe and can be used as part of daily checks on a script server somewhere.

  • @JoeCalcio24
    @JoeCalcio24 2 ปีที่แล้ว

    Excellent coverage of checking PKI health. Where’s Brian Roma?

  • @JoeCalcio24
    @JoeCalcio24 2 ปีที่แล้ว

    Question: is enabling Directory Browsing mandatory for the ‘PKI’ site? I’ve gotten some flack for that. Thoughts?

    • @MindingtheKeystore
      @MindingtheKeystore 2 ปีที่แล้ว

      Directory browsing is not required for revocation checking, but it is handy to have enabled in order to CRL status check or troubleshoot CRL publishing issues.

  • @JoeCalcio24
    @JoeCalcio24 2 ปีที่แล้ว

    Nice Demo! I've always done the 'click through' with the GUI. Will have to try the command line method in my lab. Also, looking for the script you used for the install - can you please post it? Thanks!!!

    • @MindingtheKeystore
      @MindingtheKeystore 2 ปีที่แล้ว

      Good to hear from you Antonio! notes have been updated with some commands for you to play with!

  • @charleshamby9564
    @charleshamby9564 3 ปีที่แล้ว

    Was just discussing this with MSFT a week or two ago. The behavior of certificates specifically with WHfB works in unique ways that ended up causing a deep-dive in this realm. Would love to see some videos around PKI with WHfB. This is a pain-point with many orgs right now. Thanks for walking through detail MSFT seems to not want to document!

  • @rajan9018
    @rajan9018 3 ปีที่แล้ว

    Is there any standard KPI metric followed in certificate management, PKi infra

  • @pstewart5443
    @pstewart5443 3 ปีที่แล้ว

    Wow, Im your first like! Mark, you haven't responded to my email yet......:(

    • @MindingtheKeystore
      @MindingtheKeystore 3 ปีที่แล้ว

      Good to hear from you! We have sent a couple of follow-up e-mail messages but have not heard back. We wanted to check and see if maybe e-mails were getting flagged as spam perhaps?

  • @pstewart5443
    @pstewart5443 3 ปีที่แล้ว

    25 cert limit in Azure AD. The only way we found to fix this issue is to remove all certs from the user's on-prem AD and allow new certs to publish to AD with credential roaming set on a few users at a time. It's a nightmare painful scenario.

  • @JoeCalcio24
    @JoeCalcio24 3 ปีที่แล้ว

    Yet another great segment! Just one ‘ask’ … can you include the certutil commands that you used in the description? Thanks!

  • @chrisursich
    @chrisursich 3 ปีที่แล้ว

    Repeatedly building lab infrastructure manually has been very time-consuming for me, and I have been looking for a way to automate it. This is going to be great. Thanks for the video.

  • @MindingtheKeystore
    @MindingtheKeystore 3 ปีที่แล้ว

    Do you still have SHA1 CAs in your environment?

  • @JoeCalcio24
    @JoeCalcio24 3 ปีที่แล้ว

    Great primer for an “offline” root CA! Looking forward to intermediate CAs. Thanks.

  • @Tony-ub7xf
    @Tony-ub7xf 3 ปีที่แล้ว

    Just completed the Autolab setup on a Windows 10 Pro PC. Looking forward to more Autolab videos to do PKI!

    • @MindingtheKeystore
      @MindingtheKeystore 3 ปีที่แล้ว

      Glad you took the plunge! We have more content coming on Managing Autolab and building ADCS there too!

  • @JoeCalcio24
    @JoeCalcio24 3 ปีที่แล้ว

    Hey Brian ... I can't get passed doing the 'setup-lab' ... getting errors in PowerShell ... At C:\AutoLab\Configurations\MultiRole-Server-2016\VMConfiguration.ps1:23 chr:5 Import-DSCresource -moduleName @{ModuleName = "PSDisredStateConf ... Could not find the module '<xPendingReboot, 0.4.0.0>'. At C:\AutoLab\configurations\MultiRole-Server-2016\VMConfiguration.ps1:414 char:9 xAdcsCertificationAuthority ADCSConfig Any advice to fix this?

    • @JoeCalcio24
      @JoeCalcio24 3 ปีที่แล้ว

      I contacted AutoLab support and it may be that the machine I was using did not have enough disk space. I switched over to a machine with more room. Plus, I ran 'Setup-Lab -ignorependingreboot' and it looks like it's working now.

    • @MindingtheKeystore
      @MindingtheKeystore 3 ปีที่แล้ว

      Thanks for your patience, Antonio. This message thread was held in quarantine by TH-cam. Took me a bit to see and release it. Appreciate your patience!

  • @MindingtheKeystore
    @MindingtheKeystore 3 ปีที่แล้ว

    What Windows Server Operating System are you focused on as you test in your lab?

  • @bethgemeny4546
    @bethgemeny4546 3 ปีที่แล้ว

    Thank you Jake, Mark, Vadims and Brian for addressing the WHfB question. I had to tune into the recording to catch it. Cheers!

    • @markcooper7441
      @markcooper7441 3 ปีที่แล้ว

      Absolutely - thanks for tuning in!

    • @MindingtheKeystore
      @MindingtheKeystore 3 ปีที่แล้ว

      Glad to have you check out the replay!

  • @MindingtheKeystore
    @MindingtheKeystore 3 ปีที่แล้ว

    I didn't realize that text in my second capture session was going to be this small. I will make sure text is bigger for next episode! Here are a list of paths and commands with time codes in case you can't read the screen: 8:27 Config files are found under Autolab\Configurations 8:36 PowerShell command is Setup-Lab 10:39 PowerShell command is Run-Lab 11:35 PowerShell command is Enable-Internet 12:00 PowerShell command is Validate-Lab 12:42 PowerShell command is Invoke-Pester .\vmvalidate.test.ps1 13:58 Some system variables (like passwords) are configured in the VMConfigurationData.ps1 file 15:12 PowerShell command is Get-WindowsCapability Name RSAT* -Online | Add-WindowsCapability -Online

  • @rajan9018
    @rajan9018 3 ปีที่แล้ว

    Hi Brian , can this module run on Windows 10 Home edition?

    • @MindingtheKeystore
      @MindingtheKeystore 3 ปีที่แล้ว

      Hyper-V can only be enabled on Windows 10 Pro, Education and Enterprise editions.

  • @MindingtheKeystore
    @MindingtheKeystore 3 ปีที่แล้ว

    With what virtualization solution do you prefer to use to build your lab?

    • @KailashNathan
      @KailashNathan 3 ปีที่แล้ว

      We're a VMware shop, so I've mostly been using VMWare Workstation. I haven't really used Hyper-V and don't know the differences/advantage to it. I was wanting to script out an ADCS lab, and I'll try this sometime. Thanks!

    • @MindingtheKeystore
      @MindingtheKeystore 3 ปีที่แล้ว

      @@KailashNathan I have a special place in my heart for VMWare products, but wanted to make a video that was lower budget to get going.