Hello,
after running the Ansible-Playbook, we couldn't see the template was actually vulnerable to ESC1. When we investigated, we found the "Enroll"-checkbox that was neccessary for authenticated users to generate the certificate (in theory, obviously not for real as this is a honeypot) for a higher-privilege user.

Anybody else have this problem?
Kind regards,
Gearanach