*** This bug is a security vulnerability ***

Private security bug reported:

**Title:** Certificate auto-enrollment settings silently ignored when
registry paths use uppercase `SOFTWARE`

**Description**

ADSys appears to match certificate enrollment registry paths case-
sensitively. Our GPO contains paths beginning with `SOFTWARE`, while the
matching code expects `Software`. Windows registry key names are case-
insensitive.

As a result, ADSys retrieves and parses the GPO and lists it in applied
policies, but omits its certificate settings and does not initiate
enrollment. The policy refresh completes without an obvious error
identifying the skipped settings.

**Affected environment**

- Ubuntu 22.04, host `lt001237w`
- Stock ADSys client and daemon: `0.16.3~22.04.2ubuntu0.22.04.1`
- Ubuntu Pro enabled
- GPO: `Linux Certificate Auto-Enrollment`
- GPO ID: `{9B8F0CA0-96EF-4672-8733-095719DDDD52}`
- Local and remote GPO version: `65545`

The issue was also investigated on Ubuntu 24.04 using ADSys
`0.16.3~24.04.2ubuntu0.24.04.1`, where a local casing patch enabled
certificate-policy processing.

**Reproduction**

1. Configure a computer certificate auto-enrollment GPO whose 
`Machine/Registry.pol` contains:
   ```
   SOFTWARE\Policies\Microsoft\Cryptography\AutoEnrollment
       AEPolicy

   SOFTWARE\Policies\Microsoft\Cryptography\PolicyServers
   ```
2. Apply the GPO to an Ubuntu computer running stock ADSys.
3. Run:
   ```bash
   sudo adsysctl policy update -m -vvv
   sudo adsysctl policy applied -m --details --all
   sudo getcert list
   ```

**Actual result**

The debug log confirms that ADSys finds and parses the certificate GPO’s
`Machine/Registry.pol`. However:

- No certificate settings appear under that GPO in detailed applied-policy 
output.
- No certificate enrollment helper invocation appears in the captured refresh 
log.
- Certmonger reports zero tracked requests.

The downloaded policy file’s SHA-256 is:

```text
8165f411b061c84027a811ae8727db0304f37796f6c34c4d76ec58836a80a1a4
```

**Expected result**

ADSys should recognize equivalent registry paths regardless of
capitalization and process the configured certificate enrollment
settings.

**Suspected cause and proposed fix**

In `internal/ad/ad.go`, certificate settings are identified using case-
sensitive comparisons:

```go
pol.Key == certAutoEnrollKey
strings.HasPrefix(pol.Key, policyServersPrefix)
```

Our local patch uses case-insensitive comparisons and canonicalizes the
matched policy-server prefix while preserving the remaining identifier,
value name, and data.

**Validation performed**

On Ubuntu 24.04, the patched package recognized `autoenroll=7` and the
policy-server settings. After resolving separate CEP/CES server
configuration and TLS issues, enrollment successfully issued
certificates.

On Ubuntu 22.04, we have reproduced the omission using the stock package
and verified uppercase `SOFTWARE` in the downloaded policy. A patched
before/after comparison on that host remains pending.

The patch also includes a regression test covering canonical,
uppercase-`SOFTWARE`, fully uppercase, and lowercase path variants.

**Impact**

Affected clients can report a successful GPO refresh while silently
omitting certificate enrollment settings, making the problem difficult
to distinguish from CA, template, or enrollment-service configuration
issues.

ProblemType: Bug
DistroRelease: Ubuntu 22.04
Package: adsys 0.16.3~22.04.2ubuntu0.22.04.1
ProcVersionSignature: Ubuntu 6.8.0-138.138~22.04.1-generic 6.8.12
Uname: Linux 6.8.0-138-generic x86_64
NonfreeKernelModules: lkp_Ubuntu_6_8_0_138_138_generic_121
ApportVersion: 2.20.11-0ubuntu82.10
Architecture: amd64
CasperMD5CheckResult: pass
Date: Wed Sep 30 14:17:45 2026
InstallationDate: Installed on 2026-09-30 (0 days ago)
InstallationMedia: Ubuntu 22.04.5 LTS "Jammy Jellyfish" - Release amd64 
(20240911)
ProcEnviron:
 SHELL=/bin/bash
 LANG=en_US.UTF-8
 TERM=xterm-256color
 PATH=(custom, no user)
RelatedPackageVersions:
 sssd          2.6.3-1ubuntu3.9
 python3-samba 2:4.15.13+dfsg-0ubuntu1.13
SourcePackage: adsys
UpgradeStatus: No upgrade log present (probably fresh install)
modified.conffile..etc.polkit-1.localauthority.conf.d.99-adsys-privilege-enforcement.conf:
 [deleted]
modified.conffile..etc.sudoers.d.99-adsys-privilege-enforcement: [deleted]

** Affects: adsys (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug jammy

** Information type changed from Public to Private Security

** Attachment removed: "Dependencies.txt"
   
https://bugs.launchpad.net/ubuntu/+source/adsys/+bug/2169074/+attachment/6004004/+files/Dependencies.txt

** Attachment removed: "Syslog.txt"
   
https://bugs.launchpad.net/ubuntu/+source/adsys/+bug/2169074/+attachment/6004007/+files/Syslog.txt

** Attachment removed: "JournalErrors.txt"
   
https://bugs.launchpad.net/ubuntu/+source/adsys/+bug/2169074/+attachment/6004005/+files/JournalErrors.txt

** Attachment removed: "ProcCpuinfoMinimal.txt"
   
https://bugs.launchpad.net/ubuntu/+source/adsys/+bug/2169074/+attachment/6004006/+files/ProcCpuinfoMinimal.txt

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169074

Title:
  Adsys is case sensitive when querying registery
  \SOFTWARE\Policies\Microsoft\Cryptography\

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/adsys/+bug/2169074/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to