From 30b9b9ddbfaada7dbc94e28bd508c6a129c630ba Mon Sep 17 00:00:00 2001 From: Travis Plunk Date: Thu, 10 Oct 2024 12:28:43 -0700 Subject: [PATCH] Revert "Add windows signing for pwsh.exe (#24219) (#24306)" (#24408) This reverts commit f0461bc00f673ac20c2531d3006813ba692e7ba1. --- .pipelines/templates/obp-file-signing.yml | 25 ----------------------- 1 file changed, 25 deletions(-) diff --git a/.pipelines/templates/obp-file-signing.yml b/.pipelines/templates/obp-file-signing.yml index 7ed973ddf5..ba761633b2 100644 --- a/.pipelines/templates/obp-file-signing.yml +++ b/.pipelines/templates/obp-file-signing.yml @@ -84,31 +84,6 @@ steps: files_to_sign: '**\*.psd1;**\*.psm1;**\*.ps1xml;**\*.ps1;**\*.dll;**\*.exe;**\pwsh' search_root: $(Pipeline.Workspace)/toBeSigned -- task: onebranch.pipeline.signing@1 - displayName: Sign pwsh.exe with Windows cert - inputs: - command: 'sign' - cp_code: '203' - files_to_sign: '**\pwsh.exe' - search_root: $(Pipeline.Workspace)/toBeSigned - -- pwsh: | - if (Test-Path $(Pipeline.Workspace)/toBeSigned/pwsh.exe) { - Write-Verbose -Verbose "pwsh.exe is found, verifying signature" - $signature = Get-AuthenticodeSignature -FilePath $(Pipeline.Workspace)/toBeSigned/pwsh.exe - if ($signature.SignerCertificate.Issuer -notmatch '^CN=Microsoft Windows Production.*') { - Write-Error -ErrorAction Stop "pwsh.exe is not signed by Microsoft" - } - else { - Write-Verbose -Verbose "pwsh.exe is signed by Microsoft" - } - } - else { - Write-Verbose -Verbose "pwsh.exe is not found, skipping" - } - - displayName: 'Verify windows signature' - - pwsh : | Get-ChildItem -Path env: displayName: Capture environment