Add SkipCA and SkipCN check requirement to WinRM/OMI HTTPS connection (#8279)

This commit is contained in:
Paul Higinbotham
2018-11-27 16:16:00 -08:00
committed by Aditya Patwardhan
parent 9510fe56f5
commit 06571637e4
9 changed files with 107 additions and 4 deletions
@@ -138,7 +138,6 @@
<Compile Remove="engine\remoting\commands\ConnectPSSession.cs" />
<Compile Remove="engine\remoting\commands\CustomShellCommands.cs" />
<Compile Remove="engine\remoting\commands\DisconnectPSSession.cs" />
<Compile Remove="engine\remoting\commands\NewPSSessionOptionCommand.cs" />
<Compile Remove="engine\remoting\commands\ReceivePSSession.cs" />
<Compile Remove="engine\remoting\commands\TestPSSessionConfigurationFile.cs" />
</ItemGroup>
@@ -5264,7 +5264,6 @@ end
{"Get-PSSessionCapability", new SessionStateCmdletEntry("Get-PSSessionCapability", typeof(GetPSSessionCapabilityCommand), helpFile) },
{"Get-PSSessionConfiguration", new SessionStateCmdletEntry("Get-PSSessionConfiguration", typeof(GetPSSessionConfigurationCommand), helpFile) },
{"New-PSSessionConfigurationFile", new SessionStateCmdletEntry("New-PSSessionConfigurationFile", typeof(NewPSSessionConfigurationFileCommand), helpFile) },
{"New-PSSessionOption", new SessionStateCmdletEntry("New-PSSessionOption", typeof(NewPSSessionOptionCommand), helpFile) },
{"Receive-PSSession", new SessionStateCmdletEntry("Receive-PSSession", typeof(ReceivePSSessionCommand), helpFile) },
{"Register-PSSessionConfiguration", new SessionStateCmdletEntry("Register-PSSessionConfiguration", typeof(RegisterPSSessionConfigurationCommand), helpFile) },
{"Unregister-PSSessionConfiguration", new SessionStateCmdletEntry("Unregister-PSSessionConfiguration", typeof(UnregisterPSSessionConfigurationCommand), helpFile) },
@@ -5294,6 +5293,7 @@ end
{"New-ModuleManifest", new SessionStateCmdletEntry("New-ModuleManifest", typeof(NewModuleManifestCommand), helpFile) },
{"New-PSRoleCapabilityFile", new SessionStateCmdletEntry("New-PSRoleCapabilityFile", typeof(NewPSRoleCapabilityFileCommand), helpFile) },
{"New-PSSession", new SessionStateCmdletEntry("New-PSSession", typeof(NewPSSessionCommand), helpFile) },
{"New-PSSessionOption", new SessionStateCmdletEntry("New-PSSessionOption", typeof(NewPSSessionOptionCommand), helpFile) },
{"New-PSTransportOption", new SessionStateCmdletEntry("New-PSTransportOption", typeof(NewPSTransportOptionCommand), helpFile) },
{"Out-Default", new SessionStateCmdletEntry("Out-Default", typeof(OutDefaultCommand), helpFile) },
{"Out-Host", new SessionStateCmdletEntry("Out-Host", typeof(OutHostCommand), helpFile) },
@@ -20,6 +20,7 @@ namespace Microsoft.PowerShell.Commands
{
#region Parameters (specific to PSSessionOption)
#if !UNIX
/// <summary>
/// The MaximumRedirection parameter enables the implicit redirection functionality
/// -1 = no limit
@@ -178,11 +179,13 @@ namespace Microsoft.PowerShell.Commands
set { _idleTimeout = value; }
}
private int? _idleTimeout;
#endif
#endregion Parameters
#region Parameters copied from New-WSManSessionOption
#if !UNIX
/// <summary>
/// By default, ProxyAccessType is None, that means Proxy information (ProxyAccessType,
/// ProxyAuthenticationMechanism and ProxyCredential)is not passed to WSMan at all.
@@ -210,6 +213,7 @@ namespace Microsoft.PowerShell.Commands
[ValidateNotNullOrEmpty]
[Credential]
public PSCredential ProxyCredential { get; set; }
#endif
/// <summary>
/// The following is the definition of the input parameter "SkipCACheck".
@@ -241,6 +245,8 @@ namespace Microsoft.PowerShell.Commands
}
private bool _skipcncheck;
#if !UNIX
/// <summary>
/// The following is the definition of the input parameter "SkipRevocation".
/// Indicates that certificate common name (CN) of the server need not match the
@@ -319,6 +325,8 @@ namespace Microsoft.PowerShell.Commands
}
private bool _includePortInSPN;
#endif
#endregion
#region Implementation
@@ -330,11 +338,14 @@ namespace Microsoft.PowerShell.Commands
{
PSSessionOption result = new PSSessionOption();
// Begin: WSMan specific options
#if !UNIX
result.ProxyAccessType = this.ProxyAccessType;
result.ProxyAuthentication = this.ProxyAuthentication;
result.ProxyCredential = this.ProxyCredential;
#endif
result.SkipCACheck = this.SkipCACheck;
result.SkipCNCheck = this.SkipCNCheck;
#if !UNIX
result.SkipRevocationCheck = this.SkipRevocationCheck;
if (_operationtimeout.HasValue)
{
@@ -385,6 +396,7 @@ namespace Microsoft.PowerShell.Commands
{
result.ApplicationArguments = this.ApplicationArguments;
}
#endif
this.WriteObject(result);
}
@@ -127,6 +127,7 @@ namespace System.Management.Automation.Remoting
CannotSetStdOutHandle = 822,
CannotSetStdErrHandle = 823,
InvalidConfigurationName = 824,
ConnectSkipCheckFailed = 825,
// Error codes added to support new WSMan Fan-In Model API
CreateSessionFailed = 851,
CreateExFailed = 853,
@@ -1924,8 +1924,11 @@ namespace System.Management.Automation.Remoting.Client
0,
result1.data.binaryData.bufferLength);
}
#if !UNIX
Dbg.Assert(result1.data.type == (uint)WSManDataType.WSMAN_DATA_TYPE_BINARY,
"ReceiveDataResult can receive only binary data");
#endif
WSManReceiveDataResult result = new WSManReceiveDataResult();
result.data = dataRecvd;
@@ -1528,11 +1528,17 @@ namespace System.Management.Automation.Remoting.Client
}
#if UNIX
// explicitly disallow Basic auth over HTTP on Unix.
// Explicitly disallow Basic auth over HTTP on Unix.
if (connectionInfo.AuthenticationMechanism == AuthenticationMechanism.Basic && !isSSLSpecified && connectionUri.Scheme != Uri.UriSchemeHttps)
{
throw new PSRemotingTransportException(PSRemotingErrorId.ConnectFailed, RemotingErrorIdStrings.BasicAuthOverHttpNotSupported);
}
// Allow HTTPS on Unix only if SkipCACheck and SkipCNCheck are selected, because OMI client does not support validating server certificates.
if (isSSLSpecified && (!connectionInfo.SkipCACheck || !connectionInfo.SkipCNCheck))
{
throw new PSRemotingTransportException(PSRemotingErrorId.ConnectSkipCheckFailed, RemotingErrorIdStrings.UnixOnlyHttpsWithoutSkipCACheckNotSupported);
}
#endif
if (connectionInfo.NoEncryption)
@@ -1670,4 +1670,7 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro
<data name="CannotGetHostInteropTypes" xml:space="preserve">
<value>Host system does not have the correct version of Hyper-V schema.</value>
</data>
<data name="UnixOnlyHttpsWithoutSkipCACheckNotSupported" xml:space="preserve">
<value>HTTPS on Unix does not currently support CA or CN checks. Use the PSSessionOption -SkipCACheck and -SkipCNCheck if you are certain you trust the server you are connecting to and the network in between.</value>
</data>
</root>
@@ -340,7 +340,7 @@ Describe "Verify approved aliases list" -Tags "CI" {
"Cmdlet", "New-PSRoleCapabilityFile", , $( $CoreWindows -or $CoreUnix)
"Cmdlet", "New-PSSession", , $($FullCLR -or $CoreWindows -or $CoreUnix)
"Cmdlet", "New-PSSessionConfigurationFile", , $($FullCLR -or $CoreWindows )
"Cmdlet", "New-PSSessionOption", , $($FullCLR -or $CoreWindows )
"Cmdlet", "New-PSSessionOption", , $($FullCLR -or $CoreWindows -or $CoreUnix)
"Cmdlet", "New-PSTransportOption", , $($FullCLR -or $CoreWindows -or $CoreUnix)
"Cmdlet", "New-Service", , $($FullCLR -or $CoreWindows )
"Cmdlet", "New-TemporaryFile", , $( $CoreWindows -or $CoreUnix)
@@ -0,0 +1,79 @@
# Copyright (c) Microsoft Corporation. All rights reserved.
# Licensed under the MIT License.
#
# PSSession tests for non-Windows platforms
#
Describe "New-PSSessionOption parameters for non-Windows platforms" -Tag "CI" {
BeforeAll {
$originalDefaultParameterValues = $PSDefaultParameterValues.Clone()
if ($IsWindows) {
$PSDefaultParameterValues['it:skip'] = $true
}
}
AfterAll {
$global:PSDefaultParameterValues = $originalDefaultParameterValues
}
It "Verifies New-PSSessionOption parameters" {
$cmdInfo = Get-Command New-PSSessionOption
$commonParameterCount = [System.Management.Automation.Internal.CommonParameters].GetProperties().Length
$cmdInfo.Parameters.Count | Should -Be ($commonParameterCount + 2) -Because "Only -SkipCACheck and -SkipCNCheck switch parameters are available"
{ $null = $cmdInfo.ResolveParameter("SkipCACheck") } | Should -Not -Throw -Because "SkipCACheck parameter should be available"
{ $null = $cmdInfo.ResolveParameter("SkipCNCheck") } | Should -Not -Throw -Because "SkipCNCheck parameter should be available"
}
}
Describe "SkipCACheck and SkipCNCheck PSSession options are required for New-PSSession on non-Windows platforms" -Tag "CI" {
BeforeAll {
$originalDefaultParameterValues = $PSDefaultParameterValues.Clone()
if ($IsWindows) {
$PSDefaultParameterValues['it:skip'] = $true
}
else {
$userName = "User_$(Get-Random -Maximum 99999)"
$userPassword = "Password_$(Get-Random -Maximum 99999)"
$cred = [pscredential]::new($userName, (ConvertTo-SecureString -String $userPassword -AsPlainText -Force))
$soSkipCA = New-PSSessionOption -SkipCACheck
$soSkipCN = New-PSSessionOption -SkipCNCheck
}
}
AfterAll {
$global:PSDefaultParameterValues = $originalDefaultParameterValues
}
$testCases = @(
@{
Name = 'Verifies expected error when session options is missing'
ScriptBlock = { New-PSSession -cn localhost -Credential $cred -Authentication Basic -UseSSL }
ExpectedErrorCode = 825
},
@{
Name = 'Verifies expected error when SkipCACheck option is missing'
ScriptBlock = { New-PSSession -cn localhost -Credential $cred -Authentication Basic -UseSSl -SessionOption $soSkipCN }
ExpectedErrorCode = 825
},
@{
Name = 'Verifies expected error when SkipCNCheck option is missing'
ScriptBlock = { New-PSSession -cn localhost -Credential $cred -Authentication Basic -UseSSl -SessionOption $soSkipCA }
ExpectedErrorCode = 825
}
)
It "<Name>" -TestCases $testCases {
param ($scriptBlock, $expectedErrorCode)
$er = { & $scriptBlock } | Should -Throw -ErrorId 'System.Management.Automation.Remoting.PSRemotingDataStructureException,Microsoft.PowerShell.Commands.NewPSSessionCommand' -PassThru
$er.Exception.ErrorCode | Should -Be $expectedErrorCode
}
}