£32 one-time purchase, instant download

AD CS Certificate Health Report: find CRL, expiry and ESC1 risk before your PKI does

A PowerShell tool that audits your Active Directory Certificate Services Enterprise CA and turns expiring certificates, a lapsing CRL, weak templates and the ESC1 privilege-escalation pattern into one interactive report, scored 0 to 100.

Runs on the Enterprise CA server itself. Read-only: nothing changes on your CA, in Active Directory, or in the CRL.

🔒
Read-only
Never writes to your CA, Active Directory, or CRL
📊
Real lab tested
Verified against a real Enterprise CA, findings matched to real certutil output
🖥️
No agents, no cloud
Nothing installed domain-wide, nothing uploaded anywhere
🧾
One-time £32
No subscription, covers your own MSP clients too

Video Demo

See the scan, the score and the findings table, start to finish.

Everything a real PKI audit needs, scored in one place

Expiry, CRL health, weak crypto and the ESC1 privilege-escalation pattern, weighted into one number, so a single stale template never reads the same as a CA that’s about to lapse.

🏢

CA certificate & service health

Checks the CA’s own signing certificate for expiry and confirms the Certification Authority service is actually running.

Issued certificate expiry

Flags any issued certificate that’s already expired or approaching its warning window, the kind of thing that fails silently until someone notices.

🚫

CRL health

Flags a lapsed or soon-to-lapse CRL, the kind of gap that breaks revocation checking domain-wide.

🚨

ESC1 privilege-escalation detection

Flags a template that lets a low-privilege user supply their own identity and request a certificate as anyone, including a Domain Admin.

🔑

Weak cryptography detection

Flags templates with under 2048-bit keys, and a CA configured to sign with a weak hash algorithm.

🧹

Orphaned template detection

Flags a published template that hasn’t issued a certificate in a year or more, still an attack surface even when nobody uses it.

📈

0 to 100 health score

One number for the whole CA, weighted so it reflects severity, not just finding count.

🔎

Filterable findings table

Sort and filter every finding by category or severity, search by name, with full evidence and guidance behind every row.

📄

Self-contained, white label report

One HTML file, your own branding, no install, no internet connection needed to open it. Email it, print it, hand it over.

See it in action

Real screenshots from a real Enterprise CA, not a mockup.

The score card and severity breakdown, from a real Enterprise CA scored 84/100
A finding expanded to show its evidence and recommended fix
The findings table filtered to High severity only

Who it’s for

One report, three different people who need it.

🧑‍💻

MSPs and consultants

Run it against every client CA and hand over a report they can actually read, no translating required.

🏢

Internal IT and sysadmins

A health check on your own CA before an audit, a security review, or just because nobody has looked since it was built.

🛡️

Anyone who inherited a CA they didn’t build

Templates accumulate for years and nobody wants to be the one to touch them. This tells you what’s actually risky before you decide what to change.

Requirements

🖥️

Operating system

Run on the Enterprise CA server itself, the tool reads the local CA database directly.

🔒

Rights

An account that can read the CA database: CA Administrator, CA Reader, or local Administrators. Domain Admin rights are not required.

📥

Download

Delivered instantly after checkout, from your account on this site.

⚙️

Prerequisites

PowerShell 5.1 or later. Uses certutil.exe, which ships with every Windows installation. The ADCSAdministration module is used where available and the tool falls back automatically when it isn’t installed.

🏷️

Version

1.0, released 18 September 2026.

📜

Licence

For the purchasing individual or organisation, including running it for your own clients. Not for resale or redistribution. Full terms in the included LICENSE.txt.

Frequently Asked Questions

Does it need to run on the CA server itself?

Yes. It reads the local CA database directly with certutil, so it has to run on the Enterprise CA server, signed in with an account that can read that database.

Will it change anything on my CA?

No. It is entirely read-only. It never creates, changes, revokes or deletes a certificate, a template, or anything else on the CA, in Active Directory, or in the CRL. It reads and writes a report, and nothing else.

What is ESC1 and why does it matter?

ESC1 is the best-known AD CS privilege-escalation misconfiguration: a certificate template that lets the requester supply their own identity, permits client authentication, and is open to a low-privilege group. Anyone who can enrol can request a certificate for any identity, including a Domain Admin, and authenticate to the domain as that user. This tool checks every published template for that exact combination.

Can I use it for more than one client, as an MSP?

Yes. The licence covers running it for your own organisation and for your own clients, as part of the work you do for them. It is not for resale or redistribution as a standalone download.

Do I need to install anything to view the report?

No. The report is a single self-contained HTML file. Open it in any browser, no internet connection or server needed.

Can I set my own branding and thresholds on the report?

Yes. Branding, and the certificate, CA certificate, CRL and template-staleness warning windows are all set with command-line parameters, covered in the instructions included with the download.

Is there a subscription?

No. It is a one-time purchase of £32. You keep the tool and can run it as often as you like.

Version History

  • 1.0: 18 September 2026. Initial release.

Find out what’s actually happening on your CA

Delivered as an instant download after checkout. Full instructions included.

Our other pro tools

One-time purchase, read-only, real lab tested. The same standard across the whole range.

Questions before you buy?

✉️

Ask first

Not sure it covers what you need? Get in touch before you buy and we’ll tell you straight.

↩️

Refund policy

Covered by our standard refund policy if it isn’t right for you.

📋

Instructions included

Full setup and command-line reference is included in the download, no separate documentation to hunt for.