MegaBites-AI/Windows-powershell
0372
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3 4using namespace System.Security.Cryptography.X509Certificates5using namespace System.Security.Cryptography6 7function New-CmsRecipient {8 [CmdletBinding(SupportsShouldProcess = $true)]9 [OutputType([System.Security.Cryptography.X509Certificates.X509Certificate2])]10 param([String]$Name, [Switch]$Invalid, [String]$OutPfxFile)11 $hash = [HashAlgorithmName]::SHA25612 $pad = [RSASignaturePadding]::Pkcs113 $oids = [OidCollection]::new()14 $oids.Add("1.3.6.1.4.1.311.80.1") | Out-Null15 $ext1 = [X509KeyUsageExtension]::new([X509KeyUsageFlags]::DataEncipherment, $false)16 $ext2 = [X509EnhancedKeyUsageExtension]::new($oids, $false)17 $req = ([CertificateRequest]::new("CN=$Name", ([RSA]::Create(2048)), $hash, $pad))18 if (!$Invalid) { ($ext1, $ext2).ForEach( { $req.CertificateExtensions.Add($_) }) }19 $certTmp = $req.CreateSelfSigned([datetime]::Now.AddDays(-1), [datetime]::Now.AddDays(365))20 $certBytes = $certTmp.Export([X509ContentType]::Pfx, "tmp")21 [X509KeyStorageFlags[]]$flags = "PersistKeySet", "Exportable"22 $cert = [X509Certificate2]::new($certBytes, "tmp", $flags)23 if ($OutPfxFile) {24 $outfile = New-Item $OutPfxFile -Force25 [System.IO.File]::WriteAllBytes($outfile.FullName, $cert.Export([X509ContentType]::Pfx))26 }27 return $cert28}29 30Describe "CmsMessage cmdlets using X509 cert" -Tags "CI" {31 32 BeforeAll {33 Setup -Dir "certDir"34 Setup -File "vc1.pfx"35 Setup -File "vc2.pfx"36 Setup -File "certDir/vc3.pfx"37 Setup -File "message.txt" -Content "test"38 $file1 = "TestDrive:\vc1.pfx"39 $file2 = "TestDrive:\vc2.pfx"40 $messageFile = "TestDrive:\message.txt"41 $cipherFile = "TestDrive:\cipher.txt"42 $vc1 = New-CmsRecipient "ValidCms1" -OutPfxFile $file143 $vc2 = New-CmsRecipient "ValidCms2" -OutPfxFile $file244 $vc3 = New-CmsRecipient "ValidCms22" -OutPfxFile "TestDrive:\certDir\vc3.pfx"45 $ic = New-CmsRecipient "InvalidCms" -Invalid -OutPfxFile "TestDrive:\ic.pfx"46 $store = [X509Store]::new("My", [StoreLocation]::CurrentUser)47 $store.Open("ReadWrite")48 if (!$IsMacOS) {49 $store.Add($vc1)50 $store.Add($vc2)51 $store.Add($vc3)52 }53 $certContent = "54 -----BEGIN CERTIFICATE-----55 MIIDXTCCAkWgAwIBAgIQRTsRwsx0LZBHrx9z5Dag2zANBgkqhkiG9w0BAQUFADAh56 MR8wHQYDVQQDDBZNeURhdGFFbmNpcGhlcm1lbnRDZXJ0MCAXDTE0MDcyNTIyMjkz57 OVoYDzMwMTQwNzI1MjIzOTM5WjAhMR8wHQYDVQQDDBZNeURhdGFFbmNpcGhlcm1l58 bnRDZXJ0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx3SuShUvnRqn59 tYOIouJdP3wPZ5rtDi2KYPurpngGNZjM0EGDTrnhmEAI8DL4Kp6n/zz1mYVoX73+60 6uCpZX/13VDXg1neebJ261XpBX6FzxtclIQr8ywdUtrEgCnUAhgqgvO1Wwm4ogNR61 tWGCGkmlnqyaoV1j/V4KSn4WvKqSUIOZm0umGCTtNAJ6VtdpYO+uxxnRAapPUCY+62 qQ7DFzTUECIo1lMlBcuMiXj6NSFr4/D7ltkZ27jCdsZmzI7ZvRnDlfSYTPQnAO/E63 0uYn9uyKY/xfngWkUX/pe+j+10Lm1ypbASrj2Ezgf0KeZRXBwqKUOLhKheEmBJ1864 rLV27qwHeQIDAQABo4GOMIGLMA4GA1UdDwEB/wQEAwIEMDAUBgNVHSUEDTALBgkr65 BgEEAYI3UAEwRAYJKoZIhvcNAQkPBDcwNTAOBggqhkiG9w0DAgICAIAwDgYIKoZI66 hvcNAwQCAgCAMAcGBSsOAwIHMAoGCCqGSIb3DQMHMB0GA1UdDgQWBBRIyIzwInLJ67 3B+FajVUFMACf1hrxjANBgkqhkiG9w0BAQUFAAOCAQEAfFt4rmUmWfCbbwi2mCrZ68 Osq0lfVNUiZ+iLlEKga4VAI3sJZRtErnVM70eXUt7XpRaOdIfxjuXFpsgc37KyLi69 ByCORLuRC0itZVs3aba48opfMDXivxBy0ngqCPPLQsyaN9K7WnpvYV1QxiudYwwU70 8U5rFmzlwNLvc3XiyoGWaVZluk2DIJawQ5QYAU9/NMBBCbPHjTG7k0l4cpcEC+Ex71 od3RlO6/MOYuK2WB4VTxKsV80EdA3ljlu7Td8P4movnrbB4rG4wpCpk05eREkg/572 Y54Ilo9m5OSAWtdx4yfS779eebLgUs3P+dk6EKwovXMokVveZA8cenIp3QkqSpeT73 cQ==74 -----END CERTIFICATE-----75 "76 }77 78 It "Cert Store: Encrypt/Decrypt using Subject" {79 "test" | Protect-CmsMessage -To $vc1.Subject | Unprotect-CmsMessage | Should -BeExactly "test"80 "test" | Protect-CmsMessage -To $vc1.Subject, $vc2.Subject | Unprotect-CmsMessage | Should -BeExactly "test"81 }82 83 It "Cert Store: Subject with wildcard (returns single cert)" {84 "test" | Protect-CmsMessage -To "*dCms1" | Unprotect-CmsMessage | Should -BeExactly "test"85 }86 87 It "Cert Store: Subject with wrong wildcard (returns multiple certs)" {88 { "test" | Protect-CmsMessage -To "*ValidCms*" -ErrorAction Stop } | Should -Throw -ErrorId 'IdentifierMustReferenceSingleCertificate'89 }90 91 It "Cert Store: Encrypt/Decrypt using Thumbprint" {92 "test" | Protect-CmsMessage -To $vc1.Thumbprint | Unprotect-CmsMessage | Should -BeExactly "test"93 "test" | Protect-CmsMessage -To $vc1.Thumbprint, $vc2.Thumbprint | Unprotect-CmsMessage | Should -BeExactly "test"94 }95 96 It "Cert Store: Encrypt/Decrypt subject and thumbprint" {97 "test" | Protect-CmsMessage -To $vc1.Thumbprint, $vc2.Subject | Unprotect-CmsMessage | Should -BeExactly "test"98 }99 100 It "Cert Store: removing test certificates" {101 $store.Remove($vc1)102 $store.Remove($vc2)103 $store.Remove($vc3)104 if ($IsMacOS) {105 $store.Remove($ic)106 }107 108 $store.Certificates.Find("FindByThumbprint", $vc1.Thumbprint, $false).Count | Should -BeExactly 0109 $store.Certificates.Find("FindByThumbprint", $vc2.Thumbprint, $false).Count | Should -BeExactly 0110 $store.Certificates.Find("FindByThumbprint", $vc3.Thumbprint, $false).Count | Should -BeExactly 0111 $store.Certificates.Find("FindByThumbprint", $ic.Thumbprint, $false).Count | Should -BeExactly 0112 }113 114 It "Encrypting with X509Cert" {115 "test" | Protect-CmsMessage -To $vc1 | Should -BeLike '-----BEGIN CMS*'116 }117 118 It "Encrypting with base64 string" {119 "test" | Protect-CmsMessage -To $certContent | Should -BeLike '-----BEGIN CMS*'120 }121 122 It "Encrypting with multiple X509Cert" {123 "test" | Protect-CmsMessage -To $vc1, $vc2 | Should -BeLike '-----BEGIN CMS*'124 }125 126 It "Decrypt with X509Cert" {127 "test" | Protect-CmsMessage -To $vc1 | Unprotect-CmsMessage -To $vc1 | Should -BeExactly "test"128 }129 130 It "Decrypt with multiple X509Cert" {131 "test" | Protect-CmsMessage -To $vc1, $vc2 | Unprotect-CmsMessage -To $vc1, $vc2 | Should -BeExactly "test"132 }133 134 It "Encrypt with invalid cert" {135 { "test" | Protect-CmsMessage -To $ic -ErrorAction Stop } | Should -Throw -ErrorId 'CertificateCannotBeUsedForEncryption'136 }137 138 It "Encrypt with valid and invalid" {139 { "test" | Protect-CmsMessage -To $vc1, $vc2, $ic -ErrorAction Stop } | Should -Throw -ErrorId 'CertificateCannotBeUsedForEncryption'140 }141 142 It "Encrypt/Decrypt from file" {143 Protect-CmsMessage -Path $messageFile -To $vc1 -OutFile $cipherFile144 $msg = Unprotect-CmsMessage -To $vc1 -Path $cipherFile145 $msg | Should -BeExactly "test"146 }147 148 It "Get-CmsMessage from content" {149 ("test" | Protect-CmsMessage -To $vc1 | Get-CmsMessage).Content | Should -BeLike '-----BEGIN CMS*'150 }151 152 It "Get-CmsMessage from file" {153 (Get-CmsMessage -Path $cipherFile).Content | Should -BeLike '-----BEGIN CMS*'154 }155 156 It "Encrypt With Single File" {157 "test" | Protect-CmsMessage -To $file1 | Unprotect-CmsMessage -To $file1 | Should -BeExactly "test"158 }159 160 It "Encrypt With Multiple Files" {161 $msg = "test" | Protect-CmsMessage -To $file1, $file2162 ($msg | Unprotect-CmsMessage -To $file1) | Should -BeExactly "test"163 ($msg | Unprotect-CmsMessage -To $file2) | Should -BeExactly "test"164 }165 166 It "Encrypt/Decrypt with Directory" {167 "test" | Protect-CmsMessage -To "TestDrive:\certDir" | Unprotect-CmsMessage -To "TestDrive:\certDir" | Should -BeExactly "test"168 }169 170 It "Decrypt with multiple files" {171 "test" | Protect-CmsMessage -To $vc1 | Unprotect-CmsMessage -To $file1, $file2 | Should -BeExactly "test"172 }173 174 AfterAll {175 $store.Dispose()176 }177}178 