mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Disallow Basic Auth over HTTP on Unix (#6787)
Disallow Basic Auth over HTTP on Unix Fix: #6779
This commit is contained in:
committed by
Travis Plunk
parent
77d10e969e
commit
385cc1b796
@@ -1526,6 +1526,15 @@ namespace System.Management.Automation.Remoting.Client
|
||||
// config provider.
|
||||
SetWSManSessionOption(WSManNativeApi.WSManSessionOption.WSMAN_OPTION_USE_SSL, 1);
|
||||
}
|
||||
|
||||
#if UNIX
|
||||
// explicitly disallow Basic auth over HTTP on Unix.
|
||||
if (connectionInfo.AuthenticationMechanism == AuthenticationMechanism.Basic && !isSSLSpecified)
|
||||
{
|
||||
throw new PSRemotingTransportException(PSRemotingErrorId.ConnectFailed, RemotingErrorIdStrings.BasicAuthOverHttpNotSupported);
|
||||
}
|
||||
#endif
|
||||
|
||||
if (connectionInfo.NoEncryption)
|
||||
{
|
||||
// send unencrypted messages
|
||||
|
||||
@@ -1110,6 +1110,9 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro
|
||||
<data name="AuthenticationMechanismRequiresCredential" xml:space="preserve">
|
||||
<value>{0} authentication requires an explicit user name and password. Specify the user name and password by using the -Credential parameter and try the command again.</value>
|
||||
</data>
|
||||
<data name="BasicAuthOverHttpNotSupported">
|
||||
<value>Basic authentication is not supported over HTTP on Unix.</value>
|
||||
</data>
|
||||
<data name="StartJobDefinitionNotFound1" xml:space="preserve">
|
||||
<value>Cannot find a scheduled job with name {0}.</value>
|
||||
<comment>{0} is the job definition name</comment>
|
||||
|
||||
@@ -11,6 +11,20 @@ Describe "New-PSSession basic test" -Tag @("CI") {
|
||||
}
|
||||
}
|
||||
|
||||
Describe "Basic Auth over HTTP not allowed on Unix" -Tag @("CI") {
|
||||
It "New-PSSession should throw when specifying Basic Auth over HTTP on Unix" -skip:($IsWindows) {
|
||||
$password = ConvertTo-SecureString -String "password" -AsPlainText -Force
|
||||
$credential = [PSCredential]::new('username', $password)
|
||||
|
||||
$err = ({New-PSSession -ComputerName 'localhost' -Credential $credential -Authentication Basic} | Should -Throw -PassThru -ErrorId 'System.Management.Automation.Remoting.PSRemotingDataStructureException,Microsoft.PowerShell.Commands.NewPSSessionCommand')
|
||||
$err.Exception | Should -BeOfType [System.Management.Automation.Remoting.PSRemotingTransportException]
|
||||
# Should be PSRemotingErrorId.ConnectFailed
|
||||
# Ensures we are looking at teh expected instance
|
||||
$err.Exception.ErrorCode | Should -Be 801
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Describe "JEA session Transcript script test" -Tag @("Feature", 'RequireAdminOnWindows') {
|
||||
BeforeAll {
|
||||
$originalDefaultParameterValues = $PSDefaultParameterValues.Clone()
|
||||
|
||||
Reference in New Issue
Block a user