┌──(PXEThief)─(root㉿sccm-kali)-[~/cmloot/CMLootOut/SMS/data]
└─# openssl \
-in 123_8AE6B618-77EC-46CB-B1B5-88F693E_SMSTSMediaPFX.pfx \
-passin pass:8AE6B618-77EC-46CB-B1B5-88F693E \
-nokeys -clcerts | openssl x509 -text -certopt no_pubkey,no_sigdump -noout
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
13:00:00:00:1b:3f:6d:ff:d3:07:16:36:2c:00:00:00:00:00:1b
Signature Algorithm: sha256WithRSAEncryption
Issuer: DC=domain, DC=ludus, CN=ludus-CA
Validity
Not Before: Jun 2 19:35:17 2025 GMT
Not After : Jun 2 19:35:17 2026 GMT
Subject:
X509v3 extensions:
Microsoft certificate template:
0/.'+.....7.....k...............6.=...t...y..d...
X509v3 Extended Key Usage:
TLS Web Client Authentication
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
Microsoft Application Policies Extension:
0.0
..+.......
X509v3 Subject Key Identifier:
62:55:1A:83:88:8E:1B:03:0C:76:2E:84:87:5F:B2:D0:27:92:2B:DB
X509v3 Authority Key Identifier:
74:86:80:EB:30:51:04:4D:D8:32:A0:33:7D:BB:77:24:18:C5:50:65
X509v3 CRL Distribution Points:
Full Name:
URI:ldap:///CN=ludus-CA,CN=DC01,CN=CDP,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=ludus,DC=domain?certificateRevocationList?base?objectClass=cRLDistributionPoint
Authority Information Access:
CA Issuers - URI:ldap:///CN=ludus-CA,CN=AIA,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=ludus,DC=domain?cACertificate?base?objectClass=certificationAuthority
X509v3 Subject Alternative Name: critical
DNS:sccm-distro.ludus.domain