X 509 сертификат помощник ps 1

Functions/Convert-X509CertificateToBase64.ps1

I am trying to decode and get information on a certificate using PowerShell. I want to be able to have a variable $Cert and then pull information about the certificate i.e.

$Cert.Subject
$Cert.Issuer
$Cert.ValidFrom
$Cert.ValidTo

I have the certificate as a variable.

$Cert = -----BEGIN CERTIFICATE-----
Content Here
-----END CERTIFICATE-----

@jstangroome


  • You must be signed in to star a gist


  • You must be signed in to fork a gist



  • Save jstangroome/5945820 to your computer and use it in GitHub Desktop.



Save jstangroome/5945820 to your computer and use it in GitHub Desktop.

PowerShell script to retrieve the public X509 certificate from a remote TLS endpoint


[()]
(
[()]
[]
[]
)
TypeName System.Net.Sockets.TcpClient
{
( )
()
{ ( ) }
TypeName System.Net.Security.SslStream ArgumentList ( )
{
()
} {
()
}
} {
()
}
() {
( []) {
TypeName System.Security.Cryptography.X509Certificates.X509Certificate2 ArgumentList
}
}


A custom Powershell class to help with X509Certificate2 operations

A Powershell class to perform X509Certificate2 related functions without relying on PKI cmdlets

because the PKI module is not pre-installed on all OSs (Ex: On Arch Linux).

This examples how to quickly create an X509Certificate2 using X509CertHelper class.

Author : Alain Herve

License : MIT

Return it in PFX form to prevent windows throwing a security credentials not found error during sslStream.connectAsClient or HttpClient request.

Stores X509Cert2 in certificate store.

Exports the certificate data in DER format.

Check if the certificate has expired

Certificate has expired!

Check if the certificate has a specific key usage extension

Certificate does not have DigitalSignature key usage!

Certificate does not have KeyUsage extension!

Check if the certificate has a specific extended key usage

Certificate does not have Server Authentication extended key usage!

Certificate does not have ExtendedKeyUsage extension!

More Custom Tests:

Please Provide a valid certificate subjectName

Certificate Revocation Check: Perform a certificate revocation check by verifying if the certificate is listed in any certificate revocation lists (CRLs)

or if it has been revoked by the issuing certificate authority (CA).

Get the certificate chain:

Check if any certificate in the chain is revoked

Certificate is revoked

Certificate is not revoked

Key Length Check: Check the length of the public key in the certificate and ensure it meets your desired security requirements.

For example, you can check if the key length is at least 2048 bits for RSA certificates.

Convert byte length to bit length

Key length is valid

Key length is not valid

Validate the signature algorithm used to sign the certificate.

Ensure it meets your desired security standards. Ex: you can check if the certificate is signed using a strong algorithm like SHA-256.

$requiredAlgorithm can be “SHA256”, “SHA384”, or “SHA512”, among others.

Signature algorithm is valid

Signature algorithm is not valid

Validate the entire certificate chain up to the trusted root certificate.

Ensure that all intermediate certificates are present and correctly ordered in the chain, and that each certificate in the chain is valid and not expired.

Certificate chain is valid

Certificate chain is not valid

Check if the certificate includes the required Subject Alternative Names (SANs) for your specific use case, such as DNS names, IP addresses, or email addresses.

“www.example.com”,

“subdomain.example.com”,

“192.168.0.1”

Subject Alternative Name

Required SAN found in the certificate

Required SAN not found in the certificate

Validate if the certificate adheres to specific certificate policies defined by your organization or industry standards.

/!\ Not sure how to write this one!

Required certificate policy is found

Required certificate policy is not found

If you are dealing with Extended Validation (EV) certificates, perform additional checks specific to EV requirements,

such as verifying the presence of the EV OID in the certificate.

Extended Validation flag is present

Extended Validation flag is not present

Return the path to openssl executable file & Will install it if not found 🙂

Decode the Base64 content into a byte array

$CertificateBytes = [System.Convert]::FromBase64String($Cert) and it completes.
$CertificateBytes

just contains a list of numbers.

Create an X.509 certificate object from the byte array

$certificate = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2`
`$certificate.Import($certificateBytes)

Error – MethodInvocationException: Exception calling “Import” with “1” argument(s): “X509Certificate is immutable on this platform. Use the equivalent constructor instead.”

$certificate= New-Object -TypeName system.Security.Cryptography.X509Certificates.X509Certificate2($CertificateBytes)

Error – New-Object: Cannot find an overload for “X509Certificate2” and the argument count: “1608”.

$certificateBytes.Count

Decode the Base64 content into a byte array

$CertificateBytes = [System.Convert]::FromBase64String($Cert)

**Error – MethodInvocationException: Exception calling “FromBase64String” with “1” argument(s): “The input is not a valid Base-64 string as it contains a non-base 64 character, more than two padding characters, or an illegal character among the padding characters.”
**

I’ve tried to see if there are hidden characters etc.

I did make some progress when I removed the —–BEGIN CERTIFICATE—– & —–END CERTIFICATE—– from the $Cert variable

I run the command again

:/>  Winstep Nexus Dock 19.2