Security

Reporting a vulnerability

Found a vulnerability in ADCS Health Check or on certmon.de? Please report it confidentially to mail@247-it.com with the subject SECURITY and a short description – not publicly, as long as no fix is available.

  • We acknowledge receipt within 3 business days and send a first assessment within 10 business days.
  • We agree a reasonable period with you before details are published.
  • Good-faith, proportionate security research following these rules will not lead to legal action. Please only test against your own environments, never against third-party systems.

Machine-readable: /.well-known/security.txt (RFC 9116).

Security updates

  • Fixes ship in the current version on the download page; security-relevant versions are marked “Security update:” in the changelog.
  • Every version is published with its SHA-256 checksum. Compare it with Get-FileHash before running the script.
  • The script has no auto-update feature and never contacts us.

How the Health Check is built

  • It is strictly read-only and does not transmit any data.
  • It contains no third-party libraries – only PowerShell, the Windows .NET class library and our own parser for certificate data, readable in the source.
  • The report is a local HTML file without JavaScript.