diff --git a/src/Modules/Unix/Microsoft.PowerShell.Security/Microsoft.PowerShell.Security.psd1 b/src/Modules/Unix/Microsoft.PowerShell.Security/Microsoft.PowerShell.Security.psd1
index d5961d1008..c287a6cef3 100644
--- a/src/Modules/Unix/Microsoft.PowerShell.Security/Microsoft.PowerShell.Security.psd1
+++ b/src/Modules/Unix/Microsoft.PowerShell.Security/Microsoft.PowerShell.Security.psd1
@@ -7,7 +7,7 @@ ModuleVersion="7.0.0.0"
CompatiblePSEditions = @("Core")
PowerShellVersion="3.0"
FunctionsToExport = @()
-CmdletsToExport="Get-Credential", "Get-ExecutionPolicy", "Set-ExecutionPolicy", "ConvertFrom-SecureString", "ConvertTo-SecureString", "Get-PfxCertificate"
+CmdletsToExport="Get-Credential", "Get-ExecutionPolicy", "Set-ExecutionPolicy", "ConvertFrom-SecureString", "ConvertTo-SecureString", "Get-PfxCertificate" , "Protect-CmsMessage", "Unprotect-CmsMessage", "Get-CmsMessage"
AliasesToExport = @()
NestedModules="Microsoft.PowerShell.Security.dll"
HelpInfoURI = 'https://go.microsoft.com/fwlink/?linkid=2113533'
diff --git a/src/System.Management.Automation/security/SecuritySupport.cs b/src/System.Management.Automation/security/SecuritySupport.cs
index ee1058be35..b7b08491e5 100644
--- a/src/System.Management.Automation/security/SecuritySupport.cs
+++ b/src/System.Management.Automation/security/SecuritySupport.cs
@@ -142,15 +142,20 @@ namespace System.Management.Automation.Internal
switch (policy)
{
case ExecutionPolicy.Restricted:
- executionPolicy = "Restricted"; break;
+ executionPolicy = "Restricted";
+ break;
case ExecutionPolicy.AllSigned:
- executionPolicy = "AllSigned"; break;
+ executionPolicy = "AllSigned";
+ break;
case ExecutionPolicy.RemoteSigned:
- executionPolicy = "RemoteSigned"; break;
+ executionPolicy = "RemoteSigned";
+ break;
case ExecutionPolicy.Unrestricted:
- executionPolicy = "Unrestricted"; break;
+ executionPolicy = "Unrestricted";
+ break;
case ExecutionPolicy.Bypass:
- executionPolicy = "Bypass"; break;
+ executionPolicy = "Bypass";
+ break;
}
// Set the execution policy
@@ -359,12 +364,18 @@ namespace System.Management.Automation.Internal
{
switch (policy)
{
- case ExecutionPolicy.Bypass: return "Bypass";
- case ExecutionPolicy.Unrestricted: return "Unrestricted";
- case ExecutionPolicy.RemoteSigned: return "RemoteSigned";
- case ExecutionPolicy.AllSigned: return "AllSigned";
- case ExecutionPolicy.Restricted: return "Restricted";
- default: return "Restricted";
+ case ExecutionPolicy.Bypass:
+ return "Bypass";
+ case ExecutionPolicy.Unrestricted:
+ return "Unrestricted";
+ case ExecutionPolicy.RemoteSigned:
+ return "RemoteSigned";
+ case ExecutionPolicy.AllSigned:
+ return "AllSigned";
+ case ExecutionPolicy.Restricted:
+ return "Restricted";
+ default:
+ return "Restricted";
}
}
@@ -595,7 +606,7 @@ namespace System.Management.Automation.Internal
/// True on success, false otherwise.
internal static bool CertIsGoodForSigning(X509Certificate2 c)
{
- if (!CertHasPrivatekey(c))
+ if (!c.HasPrivateKey)
{
return false;
}
@@ -620,16 +631,20 @@ namespace System.Management.Automation.Internal
private static bool CertHasOid(X509Certificate2 c, string oid)
{
- Collection ekus = GetCertEKU(c);
-
- foreach (string testOid in ekus)
+ foreach (var extension in c.Extensions)
{
- if (testOid == oid)
+ if (extension is X509EnhancedKeyUsageExtension ext)
{
- return true;
+ foreach (Oid ekuOid in ext.EnhancedKeyUsages)
+ {
+ if (ekuOid.Value == oid)
+ {
+ return true;
+ }
+ }
+ break;
}
}
-
return false;
}
@@ -644,82 +659,12 @@ namespace System.Management.Automation.Internal
{
return true;
}
-
break;
}
}
-
return false;
}
- ///
- /// Check if the specified cert has a private key in it.
- ///
- /// Certificate object.
- /// True on success, false otherwise.
- internal static bool CertHasPrivatekey(X509Certificate2 cert)
- {
- return cert.HasPrivateKey;
- }
-
- ///
- /// Get the EKUs of a cert.
- ///
- /// Certificate object.
- /// A collection of cert eku strings.
- [ArchitectureSensitive]
- internal static Collection GetCertEKU(X509Certificate2 cert)
- {
- Collection ekus = new Collection();
- IntPtr pCert = cert.Handle;
- int structSize = 0;
- IntPtr dummy = IntPtr.Zero;
-
- if (Security.NativeMethods.CertGetEnhancedKeyUsage(pCert, 0, dummy,
- out structSize))
- {
- if (structSize > 0)
- {
- IntPtr ekuBuffer = Marshal.AllocHGlobal(structSize);
-
- try
- {
- if (Security.NativeMethods.CertGetEnhancedKeyUsage(pCert, 0,
- ekuBuffer,
- out structSize))
- {
- Security.NativeMethods.CERT_ENHKEY_USAGE ekuStruct =
- (Security.NativeMethods.CERT_ENHKEY_USAGE)
- Marshal.PtrToStructure(ekuBuffer);
- IntPtr ep = ekuStruct.rgpszUsageIdentifier;
- IntPtr ekuptr;
-
- for (int i = 0; i < ekuStruct.cUsageIdentifier; i++)
- {
- ekuptr = Marshal.ReadIntPtr(ep, i * Marshal.SizeOf(ep));
- string eku = Marshal.PtrToStringAnsi(ekuptr);
- ekus.Add(eku);
- }
- }
- else
- {
- throw new System.ComponentModel.Win32Exception(Marshal.GetLastWin32Error());
- }
- }
- finally
- {
- Marshal.FreeHGlobal(ekuBuffer);
- }
- }
- }
- else
- {
- throw new System.ComponentModel.Win32Exception(Marshal.GetLastWin32Error());
- }
-
- return ekus;
- }
-
///
/// Convert an int to a DWORD.
///
@@ -1138,8 +1083,10 @@ namespace System.Management.Automation
// Process the certificate if that was supplied exactly
if (_pendingCertificate != null)
{
- ProcessResolvedCertificates(purpose,
- new List { _pendingCertificate }, out error);
+ ProcessResolvedCertificates(
+ purpose,
+ new X509Certificate2Collection(_pendingCertificate),
+ out error);
if ((error != null) || (Certificates.Count != 0))
{
return;
@@ -1162,15 +1109,8 @@ namespace System.Management.Automation
return;
}
- // Then by thumbprint
- ResolveFromThumbprint(sessionState, purpose, out error);
- if ((error != null) || (Certificates.Count != 0))
- {
- return;
- }
-
- // Then by Subject Name
- ResolveFromSubjectName(sessionState, purpose, out error);
+ // Then by cert store
+ ResolveFromStoreById(purpose, out error);
if ((error != null) || (Certificates.Count != 0))
{
return;
@@ -1215,7 +1155,7 @@ namespace System.Management.Automation
return;
}
- List certificatesToProcess = new List();
+ var certificatesToProcess = new X509Certificate2Collection();
try
{
X509Certificate2 newCertificate = new X509Certificate2(messageBytes);
@@ -1289,7 +1229,7 @@ namespace System.Management.Automation
resolvedPaths.Remove(path);
}
- List certificatesToProcess = new List();
+ var certificatesToProcess = new X509Certificate2Collection();
foreach (string path in resolvedPaths)
{
X509Certificate2 certificate = null;
@@ -1311,99 +1251,51 @@ namespace System.Management.Automation
}
}
- private void ResolveFromThumbprint(SessionState sessionState, ResolutionPurpose purpose, out ErrorRecord error)
+ private void ResolveFromStoreById(ResolutionPurpose purpose, out ErrorRecord error)
{
- // Quickly check that this is a thumbprint-like pattern (just hex)
- if (!System.Text.RegularExpressions.Regex.IsMatch(_identifier, "^[a-f0-9]+$", Text.RegularExpressions.RegexOptions.IgnoreCase))
- {
- error = null;
- return;
- }
-
- Collection certificates = new Collection();
-
- try
- {
- // Get first from 'My' store
- string certificatePath = sessionState.Path.Combine("Microsoft.PowerShell.Security\\Certificate::CurrentUser\\My", _identifier);
- if (sessionState.InvokeProvider.Item.Exists(certificatePath))
- {
- foreach (PSObject certificateObject in sessionState.InvokeProvider.Item.Get(certificatePath))
- {
- certificates.Add(certificateObject);
- }
- }
-
- // Second from 'LocalMachine' store
- certificatePath = sessionState.Path.Combine("Microsoft.PowerShell.Security\\Certificate::LocalMachine\\My", _identifier);
- if (sessionState.InvokeProvider.Item.Exists(certificatePath))
- {
- foreach (PSObject certificateObject in sessionState.InvokeProvider.Item.Get(certificatePath))
- {
- certificates.Add(certificateObject);
- }
- }
- }
- catch (SessionStateException)
- {
- // If we got an ItemNotFound / etc., then this didn't represent a valid path.
- }
-
- List certificatesToProcess = new List();
- foreach (PSObject certificateObject in certificates)
- {
- X509Certificate2 certificate = certificateObject.BaseObject as X509Certificate2;
- if (certificate != null)
- {
- certificatesToProcess.Add(certificate);
- }
- }
-
- ProcessResolvedCertificates(purpose, certificatesToProcess, out error);
- }
-
- private void ResolveFromSubjectName(SessionState sessionState, ResolutionPurpose purpose, out ErrorRecord error)
- {
- Collection certificates = new Collection();
+ error = null;
WildcardPattern subjectNamePattern = WildcardPattern.Get(_identifier, WildcardOptions.IgnoreCase);
try
{
- // Get first from 'My' store, then 'LocalMachine'
- string[] certificatePaths = new string[] {
- "Microsoft.PowerShell.Security\\Certificate::CurrentUser\\My",
- "Microsoft.PowerShell.Security\\Certificate::LocalMachine\\My" };
+ var certificatesToProcess = new X509Certificate2Collection();
- foreach (string certificatePath in certificatePaths)
+ using (var storeCU = new X509Store("my", StoreLocation.CurrentUser))
{
- foreach (PSObject certificateObject in sessionState.InvokeProvider.ChildItem.Get(certificatePath, false))
+ storeCU.Open(OpenFlags.ReadOnly);
+ X509Certificate2Collection storeCerts = storeCU.Certificates;
+
+ if (RuntimeInformation.IsOSPlatform(OSPlatform.Windows))
{
- if (subjectNamePattern.IsMatch(certificateObject.Properties["Subject"].Value.ToString()))
+ using (var storeLM = new X509Store("my", StoreLocation.LocalMachine))
{
- certificates.Add(certificateObject);
+ storeLM.Open(OpenFlags.ReadOnly);
+ storeCerts.AddRange(storeLM.Certificates);
}
}
+
+ certificatesToProcess.AddRange(storeCerts.Find(X509FindType.FindByThumbprint, _identifier, validOnly: false));
+
+ if (certificatesToProcess.Count == 0)
+ {
+ foreach (var cert in storeCerts)
+ {
+ if (subjectNamePattern.IsMatch(cert.Subject) || subjectNamePattern.IsMatch(cert.GetNameInfo(X509NameType.SimpleName, forIssuer: false)))
+ {
+ certificatesToProcess.Add(cert);
+ }
+ }
+ }
+
+ ProcessResolvedCertificates(purpose, certificatesToProcess, out error);
}
}
catch (SessionStateException)
{
- // If we got an ItemNotFound / etc., then this didn't represent a valid path.
}
-
- List certificatesToProcess = new List();
- foreach (PSObject certificateObject in certificates)
- {
- X509Certificate2 certificate = certificateObject.BaseObject as X509Certificate2;
- if (certificate != null)
- {
- certificatesToProcess.Add(certificate);
- }
- }
-
- ProcessResolvedCertificates(purpose, certificatesToProcess, out error);
}
- private void ProcessResolvedCertificates(ResolutionPurpose purpose, List certificatesToProcess, out ErrorRecord error)
+ private void ProcessResolvedCertificates(ResolutionPurpose purpose, X509Certificate2Collection certificatesToProcess, out ErrorRecord error)
{
error = null;
HashSet processedThumbprints = new HashSet();
@@ -1418,9 +1310,14 @@ namespace System.Management.Automation
{
error = new ErrorRecord(
new ArgumentException(
- string.Format(CultureInfo.InvariantCulture,
- SecuritySupportStrings.CertificateCannotBeUsedForEncryption, certificate.Thumbprint, CertificateFilterInfo.DocumentEncryptionOid)),
- "CertificateCannotBeUsedForEncryption", ErrorCategory.InvalidData, certificate);
+ string.Format(
+ CultureInfo.InvariantCulture,
+ SecuritySupportStrings.CertificateCannotBeUsedForEncryption,
+ certificate.Thumbprint,
+ CertificateFilterInfo.DocumentEncryptionOid)),
+ "CertificateCannotBeUsedForEncryption",
+ ErrorCategory.InvalidData,
+ certificate);
return;
}
else
@@ -1455,9 +1352,14 @@ namespace System.Management.Automation
{
error = new ErrorRecord(
new ArgumentException(
- string.Format(CultureInfo.InvariantCulture,
- SecuritySupportStrings.IdentifierMustReferenceSingleCertificate, _identifier, "To")),
- "IdentifierMustReferenceSingleCertificate", ErrorCategory.LimitsExceeded, certificatesToProcess);
+ string.Format(
+ CultureInfo.InvariantCulture,
+ SecuritySupportStrings.IdentifierMustReferenceSingleCertificate,
+ _identifier,
+ arg1: "To")),
+ "IdentifierMustReferenceSingleCertificate",
+ ErrorCategory.LimitsExceeded,
+ certificatesToProcess);
Certificates.Clear();
return;
}
diff --git a/test/powershell/Modules/Microsoft.PowerShell.Security/CmsMessage2.Tests.ps1 b/test/powershell/Modules/Microsoft.PowerShell.Security/CmsMessage2.Tests.ps1
new file mode 100644
index 0000000000..f58e875935
--- /dev/null
+++ b/test/powershell/Modules/Microsoft.PowerShell.Security/CmsMessage2.Tests.ps1
@@ -0,0 +1,177 @@
+# Copyright (c) Microsoft Corporation. All rights reserved.
+# Licensed under the MIT License.
+
+using namespace System.Security.Cryptography.X509Certificates
+using namespace System.Security.Cryptography
+
+function New-CmsRecipient {
+ [CmdletBinding(SupportsShouldProcess = $true)]
+ [OutputType([System.Security.Cryptography.X509Certificates.X509Certificate2])]
+ param([String]$Name, [Switch]$Invalid, [String]$OutPfxFile)
+ $hash = [HashAlgorithmName]::SHA256
+ $pad = [RSASignaturePadding]::Pkcs1
+ $oids = [OidCollection]::new()
+ $oids.Add("1.3.6.1.4.1.311.80.1") | Out-Null
+ $ext1 = [X509KeyUsageExtension]::new([X509KeyUsageFlags]::DataEncipherment, $false)
+ $ext2 = [X509EnhancedKeyUsageExtension]::new($oids, $false)
+ $req = ([CertificateRequest]::new("CN=$Name", ([RSA]::Create(2048)), $hash, $pad))
+ if (!$Invalid) { ($ext1, $ext2).ForEach( { $req.CertificateExtensions.Add($_) }) }
+ $certTmp = $req.CreateSelfSigned([datetime]::Now.AddDays(-1), [datetime]::Now.AddDays(365))
+ $certBytes = $certTmp.Export([X509ContentType]::Pfx, "tmp")
+ [X509KeyStorageFlags[]]$flags = "PersistKeySet", "Exportable"
+ $cert = [X509Certificate2]::new($certBytes, "tmp", $flags)
+ if ($OutPfxFile) {
+ $outfile = New-Item $OutPfxFile -Force
+ [System.IO.File]::WriteAllBytes($outfile.FullName, $cert.Export([X509ContentType]::Pfx))
+ }
+ return $cert
+}
+
+Describe "CmsMessage cmdlets using X509 cert" -Tags "CI" {
+
+ BeforeAll {
+ Setup -Dir "certDir"
+ Setup -File "vc1.pfx"
+ Setup -File "vc2.pfx"
+ Setup -File "certDir/vc3.pfx"
+ Setup -File "message.txt" -Content "test"
+ $file1 = "TestDrive:\vc1.pfx"
+ $file2 = "TestDrive:\vc2.pfx"
+ $messageFile = "TestDrive:\message.txt"
+ $cipherFile = "TestDrive:\cipher.txt"
+ $vc1 = New-CmsRecipient "ValidCms1" -OutPfxFile $file1
+ $vc2 = New-CmsRecipient "ValidCms2" -OutPfxFile $file2
+ $vc3 = New-CmsRecipient "ValidCms22" -OutPfxFile "TestDrive:\certDir\vc3.pfx"
+ $ic = New-CmsRecipient "InvalidCms" -Invalid -OutPfxFile "TestDrive:\ic.pfx"
+ $store = [X509Store]::new("My", [StoreLocation]::CurrentUser)
+ $store.Open("ReadWrite")
+ if (!$IsMacOS) {
+ $store.Add($vc1)
+ $store.Add($vc2)
+ $store.Add($vc3)
+ }
+ $certContent = "
+ -----BEGIN CERTIFICATE-----
+ MIIDXTCCAkWgAwIBAgIQRTsRwsx0LZBHrx9z5Dag2zANBgkqhkiG9w0BAQUFADAh
+ MR8wHQYDVQQDDBZNeURhdGFFbmNpcGhlcm1lbnRDZXJ0MCAXDTE0MDcyNTIyMjkz
+ OVoYDzMwMTQwNzI1MjIzOTM5WjAhMR8wHQYDVQQDDBZNeURhdGFFbmNpcGhlcm1l
+ bnRDZXJ0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx3SuShUvnRqn
+ tYOIouJdP3wPZ5rtDi2KYPurpngGNZjM0EGDTrnhmEAI8DL4Kp6n/zz1mYVoX73+
+ 6uCpZX/13VDXg1neebJ261XpBX6FzxtclIQr8ywdUtrEgCnUAhgqgvO1Wwm4ogNR
+ tWGCGkmlnqyaoV1j/V4KSn4WvKqSUIOZm0umGCTtNAJ6VtdpYO+uxxnRAapPUCY+
+ qQ7DFzTUECIo1lMlBcuMiXj6NSFr4/D7ltkZ27jCdsZmzI7ZvRnDlfSYTPQnAO/E
+ 0uYn9uyKY/xfngWkUX/pe+j+10Lm1ypbASrj2Ezgf0KeZRXBwqKUOLhKheEmBJ18
+ rLV27qwHeQIDAQABo4GOMIGLMA4GA1UdDwEB/wQEAwIEMDAUBgNVHSUEDTALBgkr
+ BgEEAYI3UAEwRAYJKoZIhvcNAQkPBDcwNTAOBggqhkiG9w0DAgICAIAwDgYIKoZI
+ hvcNAwQCAgCAMAcGBSsOAwIHMAoGCCqGSIb3DQMHMB0GA1UdDgQWBBRIyIzwInLJ
+ 3B+FajVUFMACf1hrxjANBgkqhkiG9w0BAQUFAAOCAQEAfFt4rmUmWfCbbwi2mCrZ
+ Osq0lfVNUiZ+iLlEKga4VAI3sJZRtErnVM70eXUt7XpRaOdIfxjuXFpsgc37KyLi
+ ByCORLuRC0itZVs3aba48opfMDXivxBy0ngqCPPLQsyaN9K7WnpvYV1QxiudYwwU
+ 8U5rFmzlwNLvc3XiyoGWaVZluk2DIJawQ5QYAU9/NMBBCbPHjTG7k0l4cpcEC+Ex
+ od3RlO6/MOYuK2WB4VTxKsV80EdA3ljlu7Td8P4movnrbB4rG4wpCpk05eREkg/5
+ Y54Ilo9m5OSAWtdx4yfS779eebLgUs3P+dk6EKwovXMokVveZA8cenIp3QkqSpeT
+ cQ==
+ -----END CERTIFICATE-----
+ "
+ }
+
+ It "Cert Store: Encrypt/Decrypt using Subject" {
+ "test" | Protect-CmsMessage -To $vc1.Subject | Unprotect-CmsMessage | Should -BeExactly "test"
+ "test" | Protect-CmsMessage -To $vc1.Subject, $vc2.Subject | Unprotect-CmsMessage | Should -BeExactly "test"
+ }
+
+ It "Cert Store: Subject with wildcard (returns single cert)" {
+ "test" | Protect-CmsMessage -To "*dCms1" | Unprotect-CmsMessage | Should -BeExactly "test"
+ }
+
+ It "Cert Store: Subject with wrong wildcard (returns multiple certs)" {
+ { "test" | Protect-CmsMessage -To "*ValidCms*" -ErrorAction Stop } | Should -Throw -ErrorId 'IdentifierMustReferenceSingleCertificate'
+ }
+
+ It "Cert Store: Encrypt/Decrypt using Thumbprint" {
+ "test" | Protect-CmsMessage -To $vc1.Thumbprint | Unprotect-CmsMessage | Should -BeExactly "test"
+ "test" | Protect-CmsMessage -To $vc1.Thumbprint, $vc2.Thumbprint | Unprotect-CmsMessage | Should -BeExactly "test"
+ }
+
+ It "Cert Store: Encrypt/Decrypt subject and thumbprint" {
+ "test" | Protect-CmsMessage -To $vc1.Thumbprint, $vc2.Subject | Unprotect-CmsMessage | Should -BeExactly "test"
+ }
+
+ It "Cert Store: removing test certificates" {
+ $store.Remove($vc1)
+ $store.Remove($vc2)
+ $store.Remove($vc3)
+ if ($IsMacOS) {
+ $store.Remove($ic)
+ }
+
+ $store.Certificates.Find("FindByThumbprint", $vc1.Thumbprint, $false).Count | Should -BeExactly 0
+ $store.Certificates.Find("FindByThumbprint", $vc2.Thumbprint, $false).Count | Should -BeExactly 0
+ $store.Certificates.Find("FindByThumbprint", $vc3.Thumbprint, $false).Count | Should -BeExactly 0
+ $store.Certificates.Find("FindByThumbprint", $ic.Thumbprint, $false).Count | Should -BeExactly 0
+ }
+
+ It "Encrypting with X509Cert" {
+ "test" | Protect-CmsMessage -To $vc1 | Should -BeLike '-----BEGIN CMS*'
+ }
+
+ It "Encrypting with base64 string" {
+ "test" | Protect-CmsMessage -To $certContent | Should -BeLike '-----BEGIN CMS*'
+ }
+
+ It "Encrypting with multiple X509Cert" {
+ "test" | Protect-CmsMessage -To $vc1, $vc2 | Should -BeLike '-----BEGIN CMS*'
+ }
+
+ It "Decrypt with X509Cert" {
+ "test" | Protect-CmsMessage -To $vc1 | Unprotect-CmsMessage -To $vc1 | Should -BeExactly "test"
+ }
+
+ It "Decrypt with multiple X509Cert" {
+ "test" | Protect-CmsMessage -To $vc1, $vc2 | Unprotect-CmsMessage -To $vc1, $vc2 | Should -BeExactly "test"
+ }
+
+ It "Encrypt with invalid cert" {
+ { "test" | Protect-CmsMessage -To $ic -ErrorAction Stop } | Should -Throw -ErrorId 'CertificateCannotBeUsedForEncryption'
+ }
+
+ It "Encrypt with valid and invalid" {
+ { "test" | Protect-CmsMessage -To $vc1, $vc2, $ic -ErrorAction Stop } | Should -Throw -ErrorId 'CertificateCannotBeUsedForEncryption'
+ }
+
+ It "Encrypt/Decrypt from file" {
+ Protect-CmsMessage -Path $messageFile -To $vc1 -OutFile $cipherFile
+ $msg = Unprotect-CmsMessage -To $vc1 -Path $cipherFile
+ $msg | Should -BeExactly "test"
+ }
+
+ It "Get-CmsMessage from content" {
+ ("test" | Protect-CmsMessage -To $vc1 | Get-CmsMessage).Content | Should -BeLike '-----BEGIN CMS*'
+ }
+
+ It "Get-CmsMessage from file" {
+ (Get-CmsMessage -Path $cipherFile).Content | Should -BeLike '-----BEGIN CMS*'
+ }
+
+ It "Encrypt With Single File" {
+ "test" | Protect-CmsMessage -To $file1 | Unprotect-CmsMessage -To $file1 | Should -BeExactly "test"
+ }
+
+ It "Encrypt With Multiple Files" {
+ $msg = "test" | Protect-CmsMessage -To $file1, $file2
+ ($msg | Unprotect-CmsMessage -To $file1) | Should -BeExactly "test"
+ ($msg | Unprotect-CmsMessage -To $file2) | Should -BeExactly "test"
+ }
+
+ It "Encrypt/Decrypt with Directory" {
+ "test" | Protect-CmsMessage -To "TestDrive:\certDir" | Unprotect-CmsMessage -To "TestDrive:\certDir" | Should -BeExactly "test"
+ }
+
+ It "Decrypt with multiple files" {
+ "test" | Protect-CmsMessage -To $vc1 | Unprotect-CmsMessage -To $file1, $file2 | Should -BeExactly "test"
+ }
+
+ AfterAll {
+ $store.Dispose()
+ }
+}
diff --git a/test/powershell/engine/Basic/DefaultCommands.Tests.ps1 b/test/powershell/engine/Basic/DefaultCommands.Tests.ps1
index 922a123b3c..e93a7a0c51 100644
--- a/test/powershell/engine/Basic/DefaultCommands.Tests.ps1
+++ b/test/powershell/engine/Basic/DefaultCommands.Tests.ps1
@@ -260,7 +260,7 @@ Describe "Verify approved aliases list" -Tags "CI" {
"Cmdlet", "Get-AuthenticodeSignature", "", $($FullCLR -or $CoreWindows ), "", "", "None"
"Cmdlet", "Get-ChildItem", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Get-Clipboard", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
-"Cmdlet", "Get-CmsMessage", "", $($FullCLR -or $CoreWindows ), "", "", "None"
+"Cmdlet", "Get-CmsMessage", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Get-Command", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Get-ComputerInfo", "", $($FullCLR -or $CoreWindows ), "", "", "None"
"Cmdlet", "Get-ComputerRestorePoint", "", $($FullCLR ), "", "", ""
@@ -375,7 +375,7 @@ Describe "Verify approved aliases list" -Tags "CI" {
"Cmdlet", "Out-Printer", "", $($FullCLR -or $CoreWindows ), "", "", "None"
"Cmdlet", "Out-String", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Pop-Location", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
-"Cmdlet", "Protect-CmsMessage", "", $($FullCLR -or $CoreWindows ), "", "", "None"
+"Cmdlet", "Protect-CmsMessage", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Push-Location", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Read-Host", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Receive-Job", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
@@ -470,7 +470,7 @@ Describe "Verify approved aliases list" -Tags "CI" {
"Cmdlet", "Trace-Command", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Unblock-File", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "Medium"
"Cmdlet", "Undo-Transaction", "", $($FullCLR ), "", "", ""
-"Cmdlet", "Unprotect-CmsMessage", "", $($FullCLR -or $CoreWindows ), "", "", "None"
+"Cmdlet", "Unprotect-CmsMessage", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "None"
"Cmdlet", "Unregister-Event", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "Medium"
"Cmdlet", "Unregister-PSSessionConfiguration","", $($FullCLR -or $CoreWindows ), "", "", "Low"
"Cmdlet", "Update-FormatData", "", $($FullCLR -or $CoreWindows -or $CoreUnix), "", "", "Low"