MegaBites-AI/Windows-powershell
0372
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3 4# Utility to generate a self-signed certificate and sign a given package such as PowerShell.zip/appx/msi5 6[CmdletBinding()]7param (8 #Path to package - Ex: PowerShell.msi, PowerShell.appx9 [Parameter(Mandatory = $true)]10 [ValidateNotNullOrEmpty()]11 [string] $PackageFilePath12 13)14 15# function to generate a self-signed certificate16# customize parameters to makecert.exe to control certificate life time and other options17function New-SelfSignedCertificate18{19 [CmdletBinding()]20 param (21 22 #Path to save generated Certificate23 [ValidateNotNullOrEmpty()]24 [string] $CertificateFilePath = "$PWD\PowerShell.cer",25 26 #Path to save generated pvk file27 [ValidateNotNullOrEmpty()]28 [string] $PvkFilePath = "$env:Temp\PowerShell.pvk"29 30 )31 32 $makecertBinPath = "${env:ProgramFiles(x86)}\Windows Kits\10\bin\x64\MakeCert.exe"33 34 Write-Verbose "Windows 10 SDK needed - https://go.microsoft.com/fwlink/p/?LinkID=822845 - Ensure MakeCert.exe is present @ $makecertBinPath"35 if (-not (Test-Path $makecertBinPath))36 {37 throw "$makecertBinPath is required to generate a self-signed certificate"38 }39 40 Remove-Item $CertificateFilePath -Force -ErrorAction Ignore41 Remove-Item $PvkFilePath -Force -ErrorAction Ignore42 43 & $makecertBinPath -r -h 0 -n "CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" -eku 1.3.6.1.5.5.7.3.3 -pe -sv $PvkFilePath $CertificateFilePath | Write-Verbose44 45 Write-Verbose "Self-Signed Cert generated @ $CertificateFilePath"46 47 return $CertificateFilePath48}49 50# Convert private pvk file format to pfx format to be consumed by signtool.exe51function ConvertTo-Pfx52{53 [CmdletBinding()]54 param (55 56 #Path to Certificate file57 [ValidateNotNullOrEmpty()]58 [string] $CertificateFilePath = "$PWD\PowerShell.cer",59 60 #Path to pvk file61 [ValidateNotNullOrEmpty()]62 [string] $PvkFilePath = "$env:Temp\PowerShell.pvk",63 64 #Path to generated pfx file65 [ValidateNotNullOrEmpty()]66 [string] $PfxFilePath = "$env:Temp\PowerShell.pfx"67 )68 69 $pvk2pfxBinPath = "${env:ProgramFiles(x86)}\Windows Kits\10\bin\x64\pvk2pfx.exe"70 71 Write-Verbose "Windows 10 SDK needed - https://go.microsoft.com/fwlink/p/?LinkID=822845 - Ensure pvk2pfx.exe is present @ $pvk2pfxBinPath"72 if (-not (Test-Path $pvk2pfxBinPath))73 {74 throw "$pvk2pfxBinPath is required to convert pvk file to pfx file - one of the prerequisites to sign a package!"75 }76 77 Remove-Item $PfxFilePath -Force -ErrorAction Ignore78 79 & $pvk2pfxBinPath /pvk $PvkFilePath /spc $CertificateFilePath /pfx $PfxFilePath /f | Write-Verbose80 81 Write-Verbose "Pfx file generated @ $PfxFilePath"82 83 return $PfxFilePath84}85 86# Sign a given package87# this function needs the proprietary pfx file88function Sign-Package89{90 [CmdletBinding()]91 param (92 93 #Path to package - Ex: PowerShell.msi, PowerShell.appx94 [Parameter(Mandatory = $true)]95 [ValidateNotNullOrEmpty()]96 [string] $PackageFilePath,97 98 #Path to generated pfx file to sign the package99 [ValidateNotNullOrEmpty()]100 [string] $PfxFilePath = "$env:Temp\PowerShell.pfx"101 102 )103 104 $signtoolBinPath = "${env:ProgramFiles(x86)}\Windows Kits\10\bin\x64\SignTool.exe"105 106 Write-Verbose "Windows 10 SDK needed - https://go.microsoft.com/fwlink/p/?LinkID=822845 - Ensure SignTool.exe is present @ $signtoolBinPath"107 if (-not (Test-Path $signtoolBinPath))108 {109 throw "$signtoolBinPath is required to sign the package!"110 }111 112 & $signtoolBinPath sign -f $PfxFilePath -fd SHA256 -v $PackageFilePath | Write-Verbose113 114 Write-Verbose "Authenticode signing successful for $PackageFilePath"115 116 return $PackageFilePath117}118 119$certificate = New-SelfSignedCertificate -Verbose120ConvertTo-Pfx -Verbose121$signedPackage = Sign-Package -PackageFilePath $PackageFilePath -Verbose122 123Write-Output "Signed Package is available @ `'$signedPackage`'"124 125Write-Output "On Windows Full SKU - Import the self-signed certificate `'$certificate`' to TrustedStore (Import-Certificate) prior to installing the package"126 127Write-Output "On Windows Nano - Use `'$env:Windir\System32\Certoc.exe -AddStore TrustedPeople <Certificate>`' to import the self-signed certificate `'$certificate`' to TrustedStore"128 