Skip to content

Microsoft Windows (PowerShell)

Tip

Before you begin, verify that the machine is created in Certificate Manager - SaaS and that you completed the prerequisite configuration steps.

PowerShell script signing requirement

The PowerShell connector requires that you set the execution policy to AllSigned on the target machine. Only signed scripts can run.

If unsigned scripts prevent you from enabling AllSigned globally, set the execution policy to AllSigned for the service account only.

  1. Sign in to Certificate Manager - SaaS.
  2. Select Installations > Machines.
  3. Click the more options more options button at the right end of the Microsoft Windows (PowerShell) machine's row, and then select Provision.
  4. In Choose a certificate from the inventory, search for and select the certificate to provision. Review its Subject DN, Validity, and Fingerprint to confirm accuracy.
  5. In CAPI Store, select the certificate store to install the certificate.
  6. Enter a Friendly Name for the certificate.
  7. Optional: To enable export of the certificate's private key, select Allow private key to be exported.
  8. Optional: To automatically run the PowerShell script, select Installation Endpoint.

    Note

    When you enable Installation Endpoint, the PowerShell script runs to bind the provisioned certificate to Windows services. The script runs under the machine's configured service account, which also installs the certificate into the CAPI store.

    Note

    Your PowerShell script must include a bind-certificate function that accepts certificateStore and thumbprint parameters. The function runs automatically when you provision a certificate.

    Script signing requirements

    1. Import the CyberArk code signing certificate to the Trusted Publishers certificate store.
    2. Import your code signing certificate to the Trusted Publishers certificate store.
    3. Sign your PowerShell script with both certificates.
    4. Set the execution policy to AllSigned for the service account.

    CyberArk code signing certificate

    Certificate Manager - SaaS uses PowerShell scripts over WinRM to provision certificates. These scripts are signed with a DigiCert code signing certificate issued to CyberArk Software Ltd. You must import this certificate into the Trusted Publishers certificate store in the machine's CAPI store.

    Typically, your Active Directory administrators manage and distribute trusted publisher certificates through Group Policy.

    The certificate is available in PEM format:

    -----BEGIN CERTIFICATE-----
    MIIHkjCCBXqgAwIBAgIQBgA2T7ITSsnbtRYegJ4l6DANBgkqhkiG9w0BAQsFADBp
    MQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xQTA/BgNVBAMT
    OERpZ2lDZXJ0IFRydXN0ZWQgRzQgQ29kZSBTaWduaW5nIFJTQTQwOTYgU0hBMzg0
    IDIwMjEgQ0ExMB4XDTI2MDkyNDAwMDAwMFoXDTI3MDkyMzIzNTk1OVowgZkxCzAJ
    BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRQwEgYDVQQHEwtTYW50YSBD
    bGFyYTEhMB8GA1UEChMYUGFsbyBBbHRvIE5ldHdvcmtzLCBJbmMuMRkwFwYDVQQL
    ExBFbmdpbmVlcmluZyBWYWFTMSEwHwYDVQQDExhQYWxvIEFsdG8gTmV0d29ya3Ms
    IEluYy4wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDXEoMfbTbxsvVa
    m0u6eml6k/yHeA9r0yUamSW0LSOUuLzGpuq0lvuzolkMYGRqlPFXDDdOKali4HyH
    sq/xTll1UqUXfETXD/c3OMcZHStIwaWAlo5KhvffZs9qHvZ5WHB0gSoDJjUY7nM2
    TgAG6T+9xAdUFRVREMzgjFLV3LoILx4LCDhQwQndk+dMY8ngrkrE//N/G2ad15kn
    G6MEIsOTORUqXMs/9LTEkr65tUamAFOPkszlcnAQ1xmRzkCSFxw4N2LVSCWIxmrZ
    0im9/pVTXwR4XaG7R1QyzIX/wMN/cYrglJgOVt+6IbIG/S68NGZH9g5LYL2EcTP4
    Ki/3x3zEEi8UJ6IJ82tfv5e/Yr7hFg9Exzaau6rmIylr+IrjIcT0SJPX95FOEozv
    TV2lP459Wsk3mQg0M0KLF0W9EL6SwDfh+oWuejfGDAtq5TKDV/qDodECZr/8hgE5
    e0m0LajxHAT0aROSnjU4moqaN6EUKKHbCvCwMuirJKWsGx0/0D613gUywt6cEG0z
    69pJFwm3T0tAa7vUkYjD5j1UFqIy965Co7s0stexvhfQLqnsSIEYfmcAzmj94pvm
    oE/IXpCr6in91kvTv7Wvx+ZwxKX+IVMJvgQuoKw4NDBjOWNXUfZQBznrpILus8o+
    ONK1cEpXh2jAtgDdSTS+KWIEMobyEwIDAQABo4ICAzCCAf8wHwYDVR0jBBgwFoAU
    aDfg67Y7+F8Rhvv+YXsIiGX0TkIwHQYDVR0OBBYEFK24lFT/8MnwqCz4ol4xBO0N
    lfv9MD4GA1UdIAQ3MDUwMwYGZ4EMAQQBMCkwJwYIKwYBBQUHAgEWG2h0dHA6Ly93
    d3cuZGlnaWNlcnQuY29tL0NQUzAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYI
    KwYBBQUHAwMwgbUGA1UdHwSBrTCBqjBToFGgT4ZNaHR0cDovL2NybDMuZGlnaWNl
    cnQuY29tL0RpZ2lDZXJ0VHJ1c3RlZEc0Q29kZVNpZ25pbmdSU0E0MDk2U0hBMzg0
    MjAyMUNBMS5jcmwwU6BRoE+GTWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp
    Q2VydFRydXN0ZWRHNENvZGVTaWduaW5nUlNBNDA5NlNIQTM4NDIwMjFDQTEuY3Js
    MIGUBggrBgEFBQcBAQSBhzCBhDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGln
    aWNlcnQuY29tMFwGCCsGAQUFBzAChlBodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5j
    b20vRGlnaUNlcnRUcnVzdGVkRzRDb2RlU2lnbmluZ1JTQTQwOTZTSEEzODQyMDIx
    Q0ExLmNydDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4ICAQAgLKMeHbYCDN1S
    PJELMA/8BPtutmNup27jrc/5n9BGoXdrD6gJgKXJVYYsAVZpe+S3V0XDqi5N5PgR
    lw74Jr5IbPSQfrgWgL9hkMzBMoIT4R9YsAQ0lQFREgexuZhVnZXViWc7WwpSBs62
    1j+kE3E7zhCFiibnXvMjgVuAXls6SlikGuvdD/Pex7ZECz3IsS7Pf6CbqYbznTTf
    9dXIKGPyMoZDLGmedDvCQWeubqS1k9lUIv06knKZw6EY/LXENSb15kzrkF6/MfHE
    aGDpxUsLGL8DIK0kAjl2brwBWrhdVc6OPJp4SZXqjm9+/ZhC6dQQclVTb29BToug
    nN3IRBXtqHdXDkj0IEUYVuwLCx9P1IpMqOoXsDZp+CwCi6jy6jIflWpDv/5NRnZs
    iXKTbddsJLlrO21uNJusmhZcKFkq0prIoFuL6/yImG8DJ/UQGxISoGpfeURHI9JA
    V64jCRaJuydeeVENS6wm429WfgQ/fARxFg7YPRTwbHwurGQzHT/03Z2eiNgRnoi2
    xmApiycAIEu1bOdBGYZ9nUHRuoVRnESYAiNCqW3c7DqIIRpPAoCSYsBx8mPWknX8
    nXJHUFzFKDNH/j86tS43wmCgKPDW+zdarepfEmrg+lpUE3OhIHBnrB0qRxEU4N0Y
    fX7EDfCAv7velGAWDsLxrAPmCcoGhA==
    -----END CERTIFICATE-----
    

    Warning

    You're responsible for securing your PowerShell script. Use a dedicated service account with the minimum required permissions. Don't use an admin or shared account. Script signing ensures integrity after deployment but doesn't guarantee source security.

    Example

    <##################
    .NAME
        bind-certificate
    .DESCRIPTION
        Consumes a certificate from the CAPI store to bind the certificate to a Windows service
    .PARAMETER certificateStore
        The Windows certificate store location where the certificate is stored
    .PARAMETER thumbprint
        The public key hash of the certificate
    .NOTES
        Successful script execution returns exit code 0. If the script fails, it returns a non-zero exit code,
        and Certificate Manager - SaaS displays the error message in the UI.
    ##################>
    function bind-certificate( [string]$certificateStore, [string]$thumbprint )
    {
        return "Success"
    }
    

  9. In Script Path, enter the full path to the PowerShell script.

    Tip

    When you enable Installation Endpoint, the certificate is pushed to the script at this path when you save.

  10. Optional: To create the certificate without pushing it to the Windows certificate store, set Push upon saving to No.

  11. Select Save.

    Want to schedule your provisions?

    Schedule your provisions daily, weekly, or monthly. Learn more