PowerShell Tools for PKI and Secure Boot with Richard Hicks

PowerShell Tools for PKI and Secure Boot with Richard Hicks

March 2, 2026 · 59 min · Episode 217

About this episode

Richard Hicks discusses PKI security, PowerShell tools, and the importance of sharing knowledge in the tech community.

Long-time Microsoft MVP and consultant Richard Hicks joins The PowerShell Podcast to talk about ADCS security, PKI misconfigurations, and why PowerShell is a consultant’s ultimate force multiplier. Richard shares real-world stories from auditing enterprise certificate environments, explains how simple template mistakes can lead to full domain compromise, and walks through tools like Locksmith that help administrators quickly identify dangerous configurations. The conversation also explores Richard’s open-source PowerShell work, including his widely downloaded Get-UEFICertificate script for Secure Boot certificate expiration issues and his new ADPrincipalCertificate module for cleaning up unnecessary certificates published in Active Directory. Along the way, Richard reflects on career growth, publishing, consulting, and why sharing knowledge openly has been one of the biggest drivers of his long-term success.Key Takeaways:• ADCS is easy to deploy but difficult to secure — Misconfigured certificate templates, especially ESC1 scenarios, can allow instant privilege escalation and domain compromise.• PowerShell turns repetitive work into reusable tools — From UEFI certificate auditing…

More episodes of The PowerShell Podcast

Explore listener stats, chart rankings, contacts and more on the The PowerShell Podcast podcast page.