Add SGU credential provider and authentication broker

This commit is contained in:
2026-08-31 17:48:18 -06:00
parent 5e216f42a4
commit 1f43f200b4
50 changed files with 3226 additions and 236 deletions
+52
View File
@@ -0,0 +1,52 @@
[CmdletBinding()]
param(
[Parameter(Mandatory)]
[ValidateSet('BrokerServer', 'CredentialProviderClient')]
[string]$Role,
[string]$BrokerDnsName = 'sgu-auth.lci.lasalle.mx',
[string]$OutputDirectory = "$env:PUBLIC\Documents\SGU-Certificates"
)
$ErrorActionPreference = 'Stop'
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
$principal = [Security.Principal.WindowsPrincipal]::new($identity)
if (-not $principal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
throw 'Run this script from an elevated PowerShell session.'
}
New-Item -ItemType Directory -Path $OutputDirectory -Force | Out-Null
if ($Role -eq 'BrokerServer') {
$certificate = New-SelfSignedCertificate `
-DnsName $BrokerDnsName `
-CertStoreLocation Cert:\LocalMachine\My `
-KeyAlgorithm RSA -KeyLength 3072 -HashAlgorithm SHA256 `
-KeyExportPolicy NonExportable `
-NotAfter (Get-Date).AddYears(2) `
-TextExtension @('2.5.29.37={text}1.3.6.1.5.5.7.3.1')
$output = Join-Path $OutputDirectory 'sgu-auth-broker.cer'
}
else {
$certificate = New-SelfSignedCertificate `
-Subject 'CN=SGU Credential Provider Client' `
-CertStoreLocation Cert:\LocalMachine\My `
-KeyAlgorithm RSA -KeyLength 3072 -HashAlgorithm SHA256 `
-KeyExportPolicy NonExportable `
-NotAfter (Get-Date).AddYears(2) `
-TextExtension @('2.5.29.37={text}1.3.6.1.5.5.7.3.2')
$output = Join-Path $OutputDirectory 'sgu-credential-provider-client.cer'
}
Export-Certificate -Cert $certificate -FilePath $output -Force | Out-Null
# These certificates are self-signed end-entity certificates. Trust the public
# half locally as well as on the peer so valid-only certificate lookup and the
# local TLS server both reject expired/untrusted lab certificates deterministically.
Import-Certificate -FilePath $output -CertStoreLocation Cert:\LocalMachine\Root | Out-Null
[pscustomobject]@{
Role = $Role
Thumbprint = $certificate.Thumbprint
PublicCertificatePath = $output
PrivateKeyExportable = $false
TrustedLocally = $certificate.Verify()
}