Disallow Basic Auth over HTTP on Unix (#6787)

Disallow Basic Auth over HTTP on Unix

Fix: #6779
This commit is contained in:
Dan Travison
2018-05-02 14:29:10 -07:00
committed by Travis Plunk
parent 77d10e969e
commit 385cc1b796
3 changed files with 26 additions and 0 deletions
@@ -1526,6 +1526,15 @@ namespace System.Management.Automation.Remoting.Client
// config provider.
SetWSManSessionOption(WSManNativeApi.WSManSessionOption.WSMAN_OPTION_USE_SSL, 1);
}
#if UNIX
// explicitly disallow Basic auth over HTTP on Unix.
if (connectionInfo.AuthenticationMechanism == AuthenticationMechanism.Basic && !isSSLSpecified)
{
throw new PSRemotingTransportException(PSRemotingErrorId.ConnectFailed, RemotingErrorIdStrings.BasicAuthOverHttpNotSupported);
}
#endif
if (connectionInfo.NoEncryption)
{
// send unencrypted messages
@@ -1110,6 +1110,9 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro
<data name="AuthenticationMechanismRequiresCredential" xml:space="preserve">
<value>{0} authentication requires an explicit user name and password. Specify the user name and password by using the -Credential parameter and try the command again.</value>
</data>
<data name="BasicAuthOverHttpNotSupported">
<value>Basic authentication is not supported over HTTP on Unix.</value>
</data>
<data name="StartJobDefinitionNotFound1" xml:space="preserve">
<value>Cannot find a scheduled job with name {0}.</value>
<comment>{0} is the job definition name</comment>
@@ -11,6 +11,20 @@ Describe "New-PSSession basic test" -Tag @("CI") {
}
}
Describe "Basic Auth over HTTP not allowed on Unix" -Tag @("CI") {
It "New-PSSession should throw when specifying Basic Auth over HTTP on Unix" -skip:($IsWindows) {
$password = ConvertTo-SecureString -String "password" -AsPlainText -Force
$credential = [PSCredential]::new('username', $password)
$err = ({New-PSSession -ComputerName 'localhost' -Credential $credential -Authentication Basic} | Should -Throw -PassThru -ErrorId 'System.Management.Automation.Remoting.PSRemotingDataStructureException,Microsoft.PowerShell.Commands.NewPSSessionCommand')
$err.Exception | Should -BeOfType [System.Management.Automation.Remoting.PSRemotingTransportException]
# Should be PSRemotingErrorId.ConnectFailed
# Ensures we are looking at teh expected instance
$err.Exception.ErrorCode | Should -Be 801
}
}
Describe "JEA session Transcript script test" -Tag @("Feature", 'RequireAdminOnWindows') {
BeforeAll {
$originalDefaultParameterValues = $PSDefaultParameterValues.Clone()