Continue roadmap: local TLS and agent review preparation
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
$ErrorActionPreference = 'Stop'
|
||||
$certificateDirectory = Join-Path $env:LOCALAPPDATA 'SovereignAI\certs'
|
||||
$expectedDirectory = [System.IO.Path]::GetFullPath($certificateDirectory).TrimEnd('\')
|
||||
$knownFiles = @(
|
||||
'sovereignai-local-root.pem',
|
||||
'sovereignai-local-root.cer',
|
||||
'sovereignai-local-root-key.pem',
|
||||
'sovereignai-local-root.srl',
|
||||
'localhost-cert.pem',
|
||||
'localhost-cert.cer',
|
||||
'localhost-key.pem',
|
||||
'localhost.csr',
|
||||
'localhost-extensions.cnf'
|
||||
) | ForEach-Object { Join-Path $certificateDirectory $_ }
|
||||
|
||||
foreach ($path in $knownFiles) {
|
||||
$fullPath = [System.IO.Path]::GetFullPath($path)
|
||||
if (-not $fullPath.StartsWith($expectedDirectory + '\', [StringComparison]::OrdinalIgnoreCase)) {
|
||||
throw "Refusing to remove a TLS file outside the dedicated certificate folder: $fullPath"
|
||||
}
|
||||
}
|
||||
|
||||
$certutil = Get-Command certutil.exe -ErrorAction SilentlyContinue
|
||||
if (-not $certutil) { throw 'certutil.exe was not found; no certificates or files were changed.' }
|
||||
foreach ($derFile in @(
|
||||
(Join-Path $certificateDirectory 'sovereignai-local-root.cer'),
|
||||
(Join-Path $certificateDirectory 'localhost-cert.cer')
|
||||
)) {
|
||||
if (-not (Test-Path -LiteralPath $derFile -PathType Leaf)) { continue }
|
||||
$certificate = [System.Security.Cryptography.X509Certificates.X509Certificate2]::new($derFile)
|
||||
$trusted = Get-ChildItem Cert:\CurrentUser\Root | Where-Object Thumbprint -eq $certificate.Thumbprint
|
||||
if ($trusted) {
|
||||
& $certutil.Source -user -delstore Root $certificate.Thumbprint | Out-Null
|
||||
if ($LASTEXITCODE -ne 0) { throw "certutil could not remove the exact certificate $($certificate.Thumbprint)." }
|
||||
$stillTrusted = Get-ChildItem Cert:\CurrentUser\Root | Where-Object Thumbprint -eq $certificate.Thumbprint
|
||||
if ($stillTrusted) { throw "Certificate $($certificate.Thumbprint) remains in CurrentUser\Root." }
|
||||
Write-Host "Removed exact trusted certificate $($certificate.Thumbprint)."
|
||||
}
|
||||
}
|
||||
|
||||
foreach ($path in $knownFiles) {
|
||||
if (Test-Path -LiteralPath $path -PathType Leaf) { Remove-Item -LiteralPath $path -Force }
|
||||
}
|
||||
if ((Test-Path -LiteralPath $certificateDirectory -PathType Container) -and
|
||||
-not (Get-ChildItem -LiteralPath $certificateDirectory -Force)) {
|
||||
Remove-Item -LiteralPath $certificateDirectory -Force
|
||||
}
|
||||
Write-Host 'Removed only the known SovereignAI local TLS files and matching trusted certificates.'
|
||||
Reference in New Issue
Block a user