£32 one-time purchase, instant download
AD CS Certificate Health Report: find CRL, expiry and ESC1 risk before your PKI does
A PowerShell tool that audits your Active Directory Certificate Services Enterprise CA and turns expiring certificates, a lapsing CRL, weak templates and the ESC1 privilege-escalation pattern into one interactive report, scored 0 to 100.
Runs on the Enterprise CA server itself. Read-only: nothing changes on your CA, in Active Directory, or in the CRL.
Video Demo
See the scan, the score and the findings table, start to finish.
Everything a real PKI audit needs, scored in one place
Expiry, CRL health, weak crypto and the ESC1 privilege-escalation pattern, weighted into one number, so a single stale template never reads the same as a CA that’s about to lapse.
CA certificate & service health
Checks the CA’s own signing certificate for expiry and confirms the Certification Authority service is actually running.
Issued certificate expiry
Flags any issued certificate that’s already expired or approaching its warning window, the kind of thing that fails silently until someone notices.
CRL health
Flags a lapsed or soon-to-lapse CRL, the kind of gap that breaks revocation checking domain-wide.
ESC1 privilege-escalation detection
Flags a template that lets a low-privilege user supply their own identity and request a certificate as anyone, including a Domain Admin.
Weak cryptography detection
Flags templates with under 2048-bit keys, and a CA configured to sign with a weak hash algorithm.
Orphaned template detection
Flags a published template that hasn’t issued a certificate in a year or more, still an attack surface even when nobody uses it.
0 to 100 health score
One number for the whole CA, weighted so it reflects severity, not just finding count.
Filterable findings table
Sort and filter every finding by category or severity, search by name, with full evidence and guidance behind every row.
Self-contained, white label report
One HTML file, your own branding, no install, no internet connection needed to open it. Email it, print it, hand it over.
See it in action
Real screenshots from a real Enterprise CA, not a mockup.



Who it’s for
One report, three different people who need it.
MSPs and consultants
Run it against every client CA and hand over a report they can actually read, no translating required.
Internal IT and sysadmins
A health check on your own CA before an audit, a security review, or just because nobody has looked since it was built.
Anyone who inherited a CA they didn’t build
Templates accumulate for years and nobody wants to be the one to touch them. This tells you what’s actually risky before you decide what to change.
Requirements
Operating system
Run on the Enterprise CA server itself, the tool reads the local CA database directly.
Rights
An account that can read the CA database: CA Administrator, CA Reader, or local Administrators. Domain Admin rights are not required.
Download
Delivered instantly after checkout, from your account on this site.
Prerequisites
PowerShell 5.1 or later. Uses certutil.exe, which ships with every Windows installation. The ADCSAdministration module is used where available and the tool falls back automatically when it isn’t installed.
Version
1.0, released 18 September 2026.
Licence
For the purchasing individual or organisation, including running it for your own clients. Not for resale or redistribution. Full terms in the included LICENSE.txt.
Frequently Asked Questions
Does it need to run on the CA server itself?
Yes. It reads the local CA database directly with certutil, so it has to run on the Enterprise CA server, signed in with an account that can read that database.
Will it change anything on my CA?
No. It is entirely read-only. It never creates, changes, revokes or deletes a certificate, a template, or anything else on the CA, in Active Directory, or in the CRL. It reads and writes a report, and nothing else.
What is ESC1 and why does it matter?
ESC1 is the best-known AD CS privilege-escalation misconfiguration: a certificate template that lets the requester supply their own identity, permits client authentication, and is open to a low-privilege group. Anyone who can enrol can request a certificate for any identity, including a Domain Admin, and authenticate to the domain as that user. This tool checks every published template for that exact combination.
Can I use it for more than one client, as an MSP?
Yes. The licence covers running it for your own organisation and for your own clients, as part of the work you do for them. It is not for resale or redistribution as a standalone download.
Do I need to install anything to view the report?
No. The report is a single self-contained HTML file. Open it in any browser, no internet connection or server needed.
Can I set my own branding and thresholds on the report?
Yes. Branding, and the certificate, CA certificate, CRL and template-staleness warning windows are all set with command-line parameters, covered in the instructions included with the download.
Is there a subscription?
No. It is a one-time purchase of £32. You keep the tool and can run it as often as you like.
Version History
- 1.0: 18 September 2026. Initial release.
Find out what’s actually happening on your CA
Delivered as an instant download after checkout. Full instructions included.
Our other pro tools
One-time purchase, read-only, real lab tested. The same standard across the whole range.
Questions before you buy?
Ask first
Not sure it covers what you need? Get in touch before you buy and we’ll tell you straight.
Instructions included
Full setup and command-line reference is included in the download, no separate documentation to hunt for.