-
Check your certificate services
Guidance for businesses:
For those of you that have active directory domains – and especially if you use Small Business Server or Essential Server and have migrated your active directory over from these platforms check out this article I wrote for CSO online earlier.
Bottom line you may have Certificate templates you either have now due to Essentials server, or you brought it over from the active directory when you migrated to your current active directory domain. As a result you may need to adjust the certificate templates on the server – or – if you no longer have an Essentials server in your network – you may need to remove the certificate templates.
Next another issue to read up on: SANS site is showcasing an issues with certificate services. Mind you that SMB signing should be enabled in most networks anyway, so you may have some mitigation already.
Guidance for consumers:
Be glad that you don’t have a network, slightly worry about all of the businesses you interact with that do.