Relax further SSL verification checks for WSMan on non-Windows hosts with verification available (#13786)

This commit is contained in:
Jordan Borean
2020-10-16 09:57:42 -07:00
committed by GitHub
parent 49b7faa817
commit 5fe17baa3b
2 changed files with 9 additions and 4 deletions
@@ -2443,9 +2443,9 @@ namespace System.Management.Automation.Remoting.Client
/// <param name="value">
/// An int (DWORD) data.
/// </param>
/// <returns></returns>
/// <returns>Zero on success, otherwise the error code.</returns>
[DllImport(WSManNativeApi.WSManClientApiDll, SetLastError = false, CharSet = CharSet.Unicode)]
internal static extern void WSManGetSessionOptionAsDword(IntPtr wsManSessionHandle,
internal static extern int WSManGetSessionOptionAsDword(IntPtr wsManSessionHandle,
WSManSessionOption option,
out int value);
@@ -1546,8 +1546,13 @@ namespace System.Management.Automation.Remoting.Client
throw new PSRemotingTransportException(PSRemotingErrorId.ConnectFailed, RemotingErrorIdStrings.BasicAuthOverHttpNotSupported);
}
// Allow HTTPS on Unix only if SkipCACheck and SkipCNCheck are selected, because OMI client does not support validating server certificates.
if (isSSLSpecified && (!connectionInfo.SkipCACheck || !connectionInfo.SkipCNCheck))
// The OMI client distributed with PowerShell does not support validating server certificates on Unix.
// Check if third-party psrpclient and MI support the verification.
// If WSManGetSessionOptionAsDword does not return 0 then it's not supported.
bool verificationAvailable = WSManNativeApi.WSManGetSessionOptionAsDword(_wsManSessionHandle,
WSManNativeApi.WSManSessionOption.WSMAN_OPTION_SKIP_CA_CHECK, out _) == 0;
if (isSSLSpecified && !verificationAvailable && (!connectionInfo.SkipCACheck || !connectionInfo.SkipCNCheck))
{
throw new PSRemotingTransportException(PSRemotingErrorId.ConnectSkipCheckFailed, RemotingErrorIdStrings.UnixOnlyHttpsWithoutSkipCACheckNotSupported);
}