Add SGU credential provider and authentication broker
This commit is contained in:
@@ -0,0 +1,32 @@
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[ValidatePattern('^https://')]
|
||||
[string]$BrokerEndpoint,
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string]$ClientCertificateThumbprint
|
||||
)
|
||||
|
||||
$ErrorActionPreference = 'Stop'
|
||||
$credential = Get-Credential -Message 'Enter an institutional DO, AL, or AD account. The password is sent only to the configured mTLS broker.'
|
||||
$clave = $credential.UserName -replace '^.*\\', '' -replace '@.*$', ''
|
||||
$password = $credential.GetNetworkCredential().Password
|
||||
|
||||
$certificate = Get-ChildItem Cert:\LocalMachine\My |
|
||||
Where-Object Thumbprint -eq ($ClientCertificateThumbprint -replace ' ', '') |
|
||||
Select-Object -First 1
|
||||
if (-not $certificate -or -not $certificate.HasPrivateKey) {
|
||||
throw 'The client certificate with private key was not found in LocalMachine\My.'
|
||||
}
|
||||
|
||||
try {
|
||||
$body = @{ clave = $clave; password = $password } | ConvertTo-Json -Compress
|
||||
Invoke-RestMethod -Method Post -Uri $BrokerEndpoint -Certificate $certificate `
|
||||
-ContentType 'application/json' -Body $body -TimeoutSec 20
|
||||
}
|
||||
finally {
|
||||
$password = $null
|
||||
$body = $null
|
||||
$credential = $null
|
||||
}
|
||||
Reference in New Issue
Block a user