<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>BrkrOps Blog</title>
    <link>https://brkrops.ca/blog/</link>
    <description>Long-form technical writing — ADCS, PKI, identity and Windows Server.</description>
    <language>en-CA</language>
    <lastBuildDate>Thu, 06 Aug 2026 00:00:00 +0000</lastBuildDate>
    <copyright>BrkrOps Inc.</copyright>
    <atom:link href="https://brkrops.ca/blog/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The garage didn&#x27;t burn down.</title>
      <link>https://brkrops.ca/blog/the-garage-didnt-burn-down/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/the-garage-didnt-burn-down/</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
      <description>43 Domain Admins, each certain their corner is separate. Seven of them chained one delegation at a time is all it takes to own the forest.</description>
    </item>
    <item>
      <title>The registration authority makes the certificate.</title>
      <link>https://brkrops.ca/blog/the-registration-authority-makes-the-certificate/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/the-registration-authority-makes-the-certificate/</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <description>NDES signs whatever it is asked to sign. Local admin plus a weak template turns it into domain admin certificates issued by your own CA.</description>
    </item>
    <item>
      <title>The certificates that break WiFi.</title>
      <link>https://brkrops.ca/blog/the-certificates-that-break-wifi/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/the-certificates-that-break-wifi/</guid>
      <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
      <description>NDES holds two service certificates that do not auto-renew. When they expire, SCEP enrollment stops and certificate-based WiFi goes down. The one-hour fix.</description>
    </item>
    <item>
      <title>Code signing.</title>
      <link>https://brkrops.ca/blog/code-signing/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/code-signing/</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <description>An enterprise code-signing certificate on a developer&#x27;s laptop — no HSM, no audit — signs a backdoor Windows trusts. It is a Tier 0 credential, not a tool.</description>
    </item>
    <item>
      <title>The model has no answer.</title>
      <link>https://brkrops.ca/blog/the-model-has-no-answer/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/the-model-has-no-answer/</guid>
      <pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
      <description>An attacker pivots from a Tier 2 workstation to the whole forest through SCCM. The model calls SCCM, Intune and backup Tier 1 — each owns Tier 0.</description>
    </item>
    <item>
      <title>The Notary Cannot Carry the Seal</title>
      <link>https://brkrops.ca/blog/the-notary-cannot-carry-the-seal/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/the-notary-cannot-carry-the-seal/</guid>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <description>An HSM-backed CA can pass every health check and still fail to publish a CRL, because its signing key lives across a network round trip.</description>
    </item>
    <item>
      <title>Two writes.</title>
      <link>https://brkrops.ca/blog/two-writes/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/two-writes/</guid>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <description>Two things on a certificate template are called Write — the ACL, and the Supply-in-the-request setting. Confusing them opens a domain-admin path.</description>
    </item>
    <item>
      <title>Cloud PKI Is Free. Sort Of.</title>
      <link>https://brkrops.ca/blog/cloud-pki-is-free/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/cloud-pki-is-free/</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <description>Intune Cloud PKI is bundled into Microsoft 365 E5 — but almost no enterprise is 100% E5. A five-year TCO against ADCS, and what Cloud PKI still cannot do.</description>
    </item>
    <item>
      <title>The Companies I Won&#x27;t Give My Data To</title>
      <link>https://brkrops.ca/blog/the-companies-i-wont-give-my-data-to/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/the-companies-i-wont-give-my-data-to/</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <description>Twelve years building certificate infrastructure for hospitals, banks and police taught me which organizations quietly accept a known, fixable risk.</description>
    </item>
    <item>
      <title>The locked door.</title>
      <link>https://brkrops.ca/blog/the-locked-door/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/the-locked-door/</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <description>Your User template, a forgotten key recovery agent and one phished user are all an attacker needs to lock files with no decryption path.</description>
    </item>
    <item>
      <title>Your backup is the breach.</title>
      <link>https://brkrops.ca/blog/your-backup-is-the-breach/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/your-backup-is-the-breach/</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <description>Why backing up Tier 0 like a file server is how an attacker walks off with your CA&#x27;s private key — and how to back up DCs and CAs safely.</description>
    </item>
    <item>
      <title>Build the root the right way, sign your sub, get one year back.</title>
      <link>https://brkrops.ca/blog/validityperiodunits/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/validityperiodunits/</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate>
      <description>Why a CAPolicy.inf root issues one-year subordinate certificates no matter what you typed — and the ValidityPeriodUnits ceiling that controls it.</description>
    </item>
    <item>
      <title>Time to come back to CDP.</title>
      <link>https://brkrops.ca/blog/come-back-to-cdp/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/come-back-to-cdp/</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate>
      <description>Why your CRL distribution point doesn&#x27;t belong on the CA, and probably shouldn&#x27;t be in LDAP either.</description>
    </item>
    <item>
      <title>Reading an AD Certificate Template: Every Attribute, Explained</title>
      <link>https://brkrops.ca/blog/reading-ad-certificate-template-attributes/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/reading-ad-certificate-template-attributes/</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>A field guide to the attributes behind a certutil -dsTemplate dump: what each one does, and which ones you can actually change.</description>
    </item>
    <item>
      <title>NAC with X.509: the good, the bad, and the ugly.</title>
      <link>https://brkrops.ca/blog/nac-with-x509/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/nac-with-x509/</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <description>What 802.1X with EAP-TLS actually buys you, where the exceptions creep in, and why NAC is a PKI project — not a network project.</description>
    </item>
    <item>
      <title>It&#x27;s not ADCS.</title>
      <link>https://brkrops.ca/blog/certificate-templates-live-in-active-directory/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/certificate-templates-live-in-active-directory/</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <description>Where certificate templates actually live, and what that means for hardening your PKI.</description>
    </item>
    <item>
      <title>A CA is a CA.</title>
      <link>https://brkrops.ca/blog/a-ca-is-a-ca/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/a-ca-is-a-ca/</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <description>Why your Certification Authority should do exactly one thing, and what to keep off it.</description>
    </item>
    <item>
      <title>You checked your CAs.</title>
      <link>https://brkrops.ca/blog/replace-a-default-certificate-template/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/replace-a-default-certificate-template/</guid>
      <pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate>
      <description>How to replace a default certificate template, in three steps.</description>
    </item>
    <item>
      <title>Twenty-five years.</title>
      <link>https://brkrops.ca/blog/twenty-five-years-default-templates/</link>
      <guid isPermaLink="true">https://brkrops.ca/blog/twenty-five-years-default-templates/</guid>
      <pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate>
      <description>Why the default certificate templates in every ADCS install are the foundation of most ESC findings.</description>
    </item>
  </channel>
</rss>
