Active Directory Certificate Services Web Enrollment Anonymous Access
Medium Nessus Plugin ID 55133
SynopsisThe remote web server is a certificate enrollment server that anyone can access without credentials.
DescriptionThe remote web server is running the Microsoft Certificate Services.
However, the service is misconfigured in such a way that anonymous users can log into the service to request certificates, thus breaking the chain of trust.
SolutionEdit the remote web server configuration to force authentication prior to accessing the remote resource.