certsync

Install command:
brew install certsync

Dump NTDS with golden certificates and UnPAC the hash

https://github.com/zblurx/certsync

License: MIT

Development: Pull requests

Formula JSON API: /api/formula/certsync.json

Formula code: certsync.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
golden gate ✅
tahoe ✅
sequoia ✅
Linux ARM64 ✅
x86_64 ✅

Current versions:

stable ✅ 0.1.6

Revision: 12

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
cryptography 50.0.2 Cryptographic recipes and primitives for Python
python@3.14 3.14.8 Interpreted, interactive, object-oriented programming language

Uses from macOS: libffi

Binaries: certsync

Known vulnerabilities in the current version:

GHSA-jr27-m4p2-rc6r (high) Denial of Service in pyasn1 via Unbounded Recursion
GHSA-m4p7-r5rc-7g4j (high) pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
GHSA-8ppf-4f7h-5ppj (high) pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of se...
GHSA-hm4w-wwcw-mr6r (high) pyasn1: Uncontrolled resource consumption when converting decoded REAL values

Data from Homebrew/advisory-database. Run brew vulns certsync for a live check.

Analytics:

30 days90 days365 days
Installs853335
Installs on Request853335
Build Errors0