Every run died in the same place. My Ludus lab runs AD CS on the Domain Controller, so the CA callback authenticated as the DC's machine account: a server trust account rather than an ordinary workstation trust account.
Impacket's rogue SMB NetLogon path and CertiGhost's LDAP validation both set ParameterControl to K (0x800), but not E (0x20), the bit Microsoft defines for a Domain Controller.
STATUS_NOLOGON_SERVER_TRUST_ACCOUNT, every time.
I wrote up CVE-2026-56877, a Skillable SCORM launch issue where the browser supplied userId drove lab allocation while the token was the only trusted value. Skillable's answer was migration, no SCORM path fix, and a private customer advisory. That is why the public record matters for anyone doing vendor due diligence.
https://payloadforge.io/beyond-crto-skillable#SCORM#Disclosure#ThirdPartyRisk