Functions/Convert-X509CertificateToBase64.ps1
I am trying to decode and get information on a certificate using PowerShell. I want to be able to have a variable $Cert and then pull information about the certificate i.e.
$Cert.Subject
$Cert.Issuer
$Cert.ValidFrom
$Cert.ValidToI have the certificate as a variable.
$Cert = -----BEGIN CERTIFICATE-----
Content Here
-----END CERTIFICATE------
You must be signed in to star a gist -
You must be signed in to fork a gist
-
Save jstangroome/5945820 to your computer and use it in GitHub Desktop.
PowerShell script to retrieve the public X509 certificate from a remote TLS endpoint
| [()] | |
| ( | |
| [()] | |
| [] | |
| [] | |
| ) | |
| TypeName System.Net.Sockets.TcpClient | |
| { | |
| ( ) | |
| () | |
| { ( ) } | |
| TypeName System.Net.Security.SslStream ArgumentList ( ) | |
| { | |
| () | |
| } { | |
| () | |
| } | |
| } { | |
| () | |
| } | |
| () { | |
| ( []) { | |
| TypeName System.Security.Cryptography.X509Certificates.X509Certificate2 ArgumentList | |
| } | |
| } |
A custom Powershell class to help with X509Certificate2 operations
A Powershell class to perform X509Certificate2 related functions without relying on PKI cmdlets
because the PKI module is not pre-installed on all OSs (Ex: On Arch Linux).
This examples how to quickly create an X509Certificate2 using X509CertHelper class.
Author : Alain Herve
License : MIT
Return it in PFX form to prevent windows throwing a security credentials not found error during sslStream.connectAsClient or HttpClient request.
Stores X509Cert2 in certificate store.
Exports the certificate data in DER format.
Check if the certificate has expired
Certificate has expired!
Check if the certificate has a specific key usage extension
Certificate does not have DigitalSignature key usage!
Certificate does not have KeyUsage extension!
Check if the certificate has a specific extended key usage
Certificate does not have Server Authentication extended key usage!
Certificate does not have ExtendedKeyUsage extension!
More Custom Tests:
Please Provide a valid certificate subjectName
Certificate Revocation Check: Perform a certificate revocation check by verifying if the certificate is listed in any certificate revocation lists (CRLs)
or if it has been revoked by the issuing certificate authority (CA).
Get the certificate chain:
Check if any certificate in the chain is revoked
Certificate is revoked
Certificate is not revoked
Key Length Check: Check the length of the public key in the certificate and ensure it meets your desired security requirements.
For example, you can check if the key length is at least 2048 bits for RSA certificates.
Convert byte length to bit length
Key length is valid
Key length is not valid
Validate the signature algorithm used to sign the certificate.
Ensure it meets your desired security standards. Ex: you can check if the certificate is signed using a strong algorithm like SHA-256.
$requiredAlgorithm can be “SHA256”, “SHA384”, or “SHA512”, among others.
Signature algorithm is valid
Signature algorithm is not valid
Validate the entire certificate chain up to the trusted root certificate.
Ensure that all intermediate certificates are present and correctly ordered in the chain, and that each certificate in the chain is valid and not expired.
Certificate chain is valid
Certificate chain is not valid
Check if the certificate includes the required Subject Alternative Names (SANs) for your specific use case, such as DNS names, IP addresses, or email addresses.
“www.example.com”,
“subdomain.example.com”,
“192.168.0.1”
Subject Alternative Name
Required SAN found in the certificate
Required SAN not found in the certificate
Validate if the certificate adheres to specific certificate policies defined by your organization or industry standards.
/!\ Not sure how to write this one!
Required certificate policy is found
Required certificate policy is not found
If you are dealing with Extended Validation (EV) certificates, perform additional checks specific to EV requirements,
such as verifying the presence of the EV OID in the certificate.
Extended Validation flag is present
Extended Validation flag is not present
Return the path to openssl executable file & Will install it if not found 🙂
Decode the Base64 content into a byte array
$CertificateBytes = [System.Convert]::FromBase64String($Cert) and it completes.
$CertificateBytesjust contains a list of numbers.
Create an X.509 certificate object from the byte array
$certificate = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2`
`$certificate.Import($certificateBytes)Error – MethodInvocationException: Exception calling “Import” with “1” argument(s): “X509Certificate is immutable on this platform. Use the equivalent constructor instead.”
$certificate= New-Object -TypeName system.Security.Cryptography.X509Certificates.X509Certificate2($CertificateBytes)Error – New-Object: Cannot find an overload for “X509Certificate2” and the argument count: “1608”.
$certificateBytes.CountDecode the Base64 content into a byte array
$CertificateBytes = [System.Convert]::FromBase64String($Cert)**Error – MethodInvocationException: Exception calling “FromBase64String” with “1” argument(s): “The input is not a valid Base-64 string as it contains a non-base 64 character, more than two padding characters, or an illegal character among the padding characters.”
**
I’ve tried to see if there are hidden characters etc.
I did make some progress when I removed the —–BEGIN CERTIFICATE—– & —–END CERTIFICATE—– from the $Cert variable
I run the command again



