The PowerShell Podcast

PowerShell Tools for PKI and Secure Boot with Richard Hicks


Listen Later

Long-time Microsoft MVP and consultant Richard Hicks joins The PowerShell Podcast to talk about ADCS security, PKI misconfigurations, and why PowerShell is a consultant’s ultimate force multiplier. Richard shares real-world stories from auditing enterprise certificate environments, explains how simple template mistakes can lead to full domain compromise, and walks through tools like Locksmith that help administrators quickly identify dangerous configurations.

The conversation also explores Richard’s open-source PowerShell work, including his widely downloaded Get-UEFICertificate script for Secure Boot certificate expiration issues and his new ADPrincipalCertificate module for cleaning up unnecessary certificates published in Active Directory. Along the way, Richard reflects on career growth, publishing, consulting, and why sharing knowledge openly has been one of the biggest drivers of his long-term success.


Key Takeaways:
• ADCS is easy to deploy but difficult to secure — Misconfigured certificate templates, especially ESC1 scenarios, can allow instant privilege escalation and domain compromise.
• PowerShell turns repetitive work into reusable tools — From UEFI certificate auditing to Active Directory cleanup, scripting creates consistency and prevents human error.
• Sharing expertise compounds over time — Blogging, publishing modules, and speaking at conferences builds credibility, community, and long-term career momentum.

Guest Bio:
Richard Hicks is the founder and principal consultant of Richard M. Hicks Consulting, Inc. A Microsoft MVP with over 30 years of experience, he specializes in secure remote access and PKI, helping organizations deliver secure, high-performing access for today’s mobile workforce.

Resource Links:

  • Richard Hicks Website – https://richardhicks.com
  • Connect with Richard – https://richardhicks.com/connect
  • Connect with Andrew: https://andrewpla.tech/links
  • Get-UEFICertificate Script – https://www.powershellgallery.com/packages/Get-UEFICertificate
  • ADPrincipalCertificate Module – https://www.powershellgallery.com/packages/ADPrincipalCertificate
  • Locksmith ADCS Audit Tool – https://github.com/jakehildreth/Locksmith
  • PDQ Discord – https://discord.gg/PDQ
  • PowerShell Wednesdays – https://www.youtube.com/watch?v=Oa0GYX9_vj8&list=PL1mL90yFExsix-L0havb8SbZXoYRPol0B&pp=sAgC
  • The PowerShell Podcast on YouTube: https://youtu.be/4HYCAjQS2W8
  • ...more
    View all episodesView all episodes
    Download on the App Store

    The PowerShell PodcastBy PDQ.com

    • 4.9
    • 4.9
    • 4.9
    • 4.9
    • 4.9

    4.9

    31 ratings


    More shows like The PowerShell Podcast

    View all
    Hanselminutes with Scott Hanselman by Scott Hanselman

    Hanselminutes with Scott Hanselman

    382 Listeners

    The Changelog: Software Development, Open Source by Changelog Media

    The Changelog: Software Development, Open Source

    288 Listeners

    Security Now (Audio) by TWiT

    Security Now (Audio)

    2,011 Listeners

    Windows Weekly (Audio) by TWiT

    Windows Weekly (Audio)

    888 Listeners

    Software Engineering Daily by Software Engineering Daily

    Software Engineering Daily

    626 Listeners

    Risky Business by Risky Business Media

    Risky Business

    371 Listeners

    RunAs Radio by Richard Campbell

    RunAs Radio

    83 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    651 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,028 Listeners

    Click Here by Recorded Future News

    Click Here

    418 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,077 Listeners

    CoRecursive: Coding Stories by Adam Gordon Bell - Software Developer

    CoRecursive: Coding Stories

    189 Listeners

    Tech Brew Ride Home by Morning Brew

    Tech Brew Ride Home

    964 Listeners

    The Real Python Podcast by Real Python

    The Real Python Podcast

    140 Listeners

    Hacker And The Fed by Chris Tarbell & Hector Monsegur

    Hacker And The Fed

    168 Listeners