Add SGU credential provider and authentication broker
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[ValidateSet('BrokerServer', 'CredentialProviderClient')]
|
||||
[string]$Role,
|
||||
|
||||
[string]$BrokerDnsName = 'sgu-auth.lci.lasalle.mx',
|
||||
[string]$OutputDirectory = "$env:PUBLIC\Documents\SGU-Certificates"
|
||||
)
|
||||
|
||||
$ErrorActionPreference = 'Stop'
|
||||
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
|
||||
$principal = [Security.Principal.WindowsPrincipal]::new($identity)
|
||||
if (-not $principal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
|
||||
throw 'Run this script from an elevated PowerShell session.'
|
||||
}
|
||||
|
||||
New-Item -ItemType Directory -Path $OutputDirectory -Force | Out-Null
|
||||
|
||||
if ($Role -eq 'BrokerServer') {
|
||||
$certificate = New-SelfSignedCertificate `
|
||||
-DnsName $BrokerDnsName `
|
||||
-CertStoreLocation Cert:\LocalMachine\My `
|
||||
-KeyAlgorithm RSA -KeyLength 3072 -HashAlgorithm SHA256 `
|
||||
-KeyExportPolicy NonExportable `
|
||||
-NotAfter (Get-Date).AddYears(2) `
|
||||
-TextExtension @('2.5.29.37={text}1.3.6.1.5.5.7.3.1')
|
||||
$output = Join-Path $OutputDirectory 'sgu-auth-broker.cer'
|
||||
}
|
||||
else {
|
||||
$certificate = New-SelfSignedCertificate `
|
||||
-Subject 'CN=SGU Credential Provider Client' `
|
||||
-CertStoreLocation Cert:\LocalMachine\My `
|
||||
-KeyAlgorithm RSA -KeyLength 3072 -HashAlgorithm SHA256 `
|
||||
-KeyExportPolicy NonExportable `
|
||||
-NotAfter (Get-Date).AddYears(2) `
|
||||
-TextExtension @('2.5.29.37={text}1.3.6.1.5.5.7.3.2')
|
||||
$output = Join-Path $OutputDirectory 'sgu-credential-provider-client.cer'
|
||||
}
|
||||
|
||||
Export-Certificate -Cert $certificate -FilePath $output -Force | Out-Null
|
||||
# These certificates are self-signed end-entity certificates. Trust the public
|
||||
# half locally as well as on the peer so valid-only certificate lookup and the
|
||||
# local TLS server both reject expired/untrusted lab certificates deterministically.
|
||||
Import-Certificate -FilePath $output -CertStoreLocation Cert:\LocalMachine\Root | Out-Null
|
||||
[pscustomobject]@{
|
||||
Role = $Role
|
||||
Thumbprint = $certificate.Thumbprint
|
||||
PublicCertificatePath = $output
|
||||
PrivateKeyExportable = $false
|
||||
TrustedLocally = $certificate.Verify()
|
||||
}
|
||||
Reference in New Issue
Block a user