$ErrorActionPreference = 'Stop' $certificateDirectory = Join-Path $env:LOCALAPPDATA 'SovereignAI\certs' $expectedDirectory = [System.IO.Path]::GetFullPath($certificateDirectory).TrimEnd('\') $knownFiles = @( 'sovereignai-local-root.pem', 'sovereignai-local-root.cer', 'sovereignai-local-root-key.pem', 'sovereignai-local-root.srl', 'localhost-cert.pem', 'localhost-cert.cer', 'localhost-key.pem', 'localhost.csr', 'localhost-extensions.cnf' ) | ForEach-Object { Join-Path $certificateDirectory $_ } foreach ($path in $knownFiles) { $fullPath = [System.IO.Path]::GetFullPath($path) if (-not $fullPath.StartsWith($expectedDirectory + '\', [StringComparison]::OrdinalIgnoreCase)) { throw "Refusing to remove a TLS file outside the dedicated certificate folder: $fullPath" } } $certutil = Get-Command certutil.exe -ErrorAction SilentlyContinue if (-not $certutil) { throw 'certutil.exe was not found; no certificates or files were changed.' } foreach ($derFile in @( (Join-Path $certificateDirectory 'sovereignai-local-root.cer'), (Join-Path $certificateDirectory 'localhost-cert.cer') )) { if (-not (Test-Path -LiteralPath $derFile -PathType Leaf)) { continue } $certificate = [System.Security.Cryptography.X509Certificates.X509Certificate2]::new($derFile) $trusted = Get-ChildItem Cert:\CurrentUser\Root | Where-Object Thumbprint -eq $certificate.Thumbprint if ($trusted) { & $certutil.Source -user -delstore Root $certificate.Thumbprint | Out-Null if ($LASTEXITCODE -ne 0) { throw "certutil could not remove the exact certificate $($certificate.Thumbprint)." } $stillTrusted = Get-ChildItem Cert:\CurrentUser\Root | Where-Object Thumbprint -eq $certificate.Thumbprint if ($stillTrusted) { throw "Certificate $($certificate.Thumbprint) remains in CurrentUser\Root." } Write-Host "Removed exact trusted certificate $($certificate.Thumbprint)." } } foreach ($path in $knownFiles) { if (Test-Path -LiteralPath $path -PathType Leaf) { Remove-Item -LiteralPath $path -Force } } if ((Test-Path -LiteralPath $certificateDirectory -PathType Container) -and -not (Get-ChildItem -LiteralPath $certificateDirectory -Force)) { Remove-Item -LiteralPath $certificateDirectory -Force } Write-Host 'Removed only the known SovereignAI local TLS files and matching trusted certificates.'