Microsoft Windows (PowerShell)¶
Tip
Before you begin, verify that the machine is created in Certificate Manager - SaaS and that you completed the prerequisite configuration steps.
PowerShell script signing requirement
The PowerShell connector requires that you set the execution policy to AllSigned on the target machine. Only signed scripts can run.
If unsigned scripts prevent you from enabling AllSigned globally, set the execution policy to AllSigned for the service account only.
- Sign in to Certificate Manager - SaaS.
- Select Installations > Machines.
- Click the more options
button at the right end of the Microsoft Windows (PowerShell) machine's row, and then select Provision. - In Choose a certificate from the inventory, search for and select the certificate to provision. Review its Subject DN, Validity, and Fingerprint to confirm accuracy.
- In CAPI Store, select the certificate store to install the certificate.
- Enter a Friendly Name for the certificate.
- Optional: To enable export of the certificate's private key, select Allow private key to be exported.
-
Optional: To automatically run the PowerShell script, select Installation Endpoint.
Note
When you enable Installation Endpoint, the PowerShell script runs to bind the provisioned certificate to Windows services. The script runs under the machine's configured service account, which also installs the certificate into the CAPI store.
Note
Your PowerShell script must include a
bind-certificatefunction that acceptscertificateStoreandthumbprintparameters. The function runs automatically when you provision a certificate.Script signing requirements
- Import the CyberArk code signing certificate to the Trusted Publishers certificate store.
- Import your code signing certificate to the Trusted Publishers certificate store.
- Sign your PowerShell script with both certificates.
- Set the execution policy to AllSigned for the service account.
CyberArk code signing certificate
Certificate Manager - SaaS uses PowerShell scripts over WinRM to provision certificates. These scripts are signed with a DigiCert code signing certificate issued to CyberArk Software Ltd. You must import this certificate into the Trusted Publishers certificate store in the machine's CAPI store.
Typically, your Active Directory administrators manage and distribute trusted publisher certificates through Group Policy.
The certificate is available in PEM format:
-----BEGIN CERTIFICATE----- MIIHkjCCBXqgAwIBAgIQBgA2T7ITSsnbtRYegJ4l6DANBgkqhkiG9w0BAQsFADBp MQswCQYDVQQGEwJVUzEXMBUGA1UEChMORGlnaUNlcnQsIEluYy4xQTA/BgNVBAMT OERpZ2lDZXJ0IFRydXN0ZWQgRzQgQ29kZSBTaWduaW5nIFJTQTQwOTYgU0hBMzg0 IDIwMjEgQ0ExMB4XDTI2MDkyNDAwMDAwMFoXDTI3MDkyMzIzNTk1OVowgZkxCzAJ BgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRQwEgYDVQQHEwtTYW50YSBD bGFyYTEhMB8GA1UEChMYUGFsbyBBbHRvIE5ldHdvcmtzLCBJbmMuMRkwFwYDVQQL ExBFbmdpbmVlcmluZyBWYWFTMSEwHwYDVQQDExhQYWxvIEFsdG8gTmV0d29ya3Ms IEluYy4wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDXEoMfbTbxsvVa m0u6eml6k/yHeA9r0yUamSW0LSOUuLzGpuq0lvuzolkMYGRqlPFXDDdOKali4HyH sq/xTll1UqUXfETXD/c3OMcZHStIwaWAlo5KhvffZs9qHvZ5WHB0gSoDJjUY7nM2 TgAG6T+9xAdUFRVREMzgjFLV3LoILx4LCDhQwQndk+dMY8ngrkrE//N/G2ad15kn G6MEIsOTORUqXMs/9LTEkr65tUamAFOPkszlcnAQ1xmRzkCSFxw4N2LVSCWIxmrZ 0im9/pVTXwR4XaG7R1QyzIX/wMN/cYrglJgOVt+6IbIG/S68NGZH9g5LYL2EcTP4 Ki/3x3zEEi8UJ6IJ82tfv5e/Yr7hFg9Exzaau6rmIylr+IrjIcT0SJPX95FOEozv TV2lP459Wsk3mQg0M0KLF0W9EL6SwDfh+oWuejfGDAtq5TKDV/qDodECZr/8hgE5 e0m0LajxHAT0aROSnjU4moqaN6EUKKHbCvCwMuirJKWsGx0/0D613gUywt6cEG0z 69pJFwm3T0tAa7vUkYjD5j1UFqIy965Co7s0stexvhfQLqnsSIEYfmcAzmj94pvm oE/IXpCr6in91kvTv7Wvx+ZwxKX+IVMJvgQuoKw4NDBjOWNXUfZQBznrpILus8o+ ONK1cEpXh2jAtgDdSTS+KWIEMobyEwIDAQABo4ICAzCCAf8wHwYDVR0jBBgwFoAU aDfg67Y7+F8Rhvv+YXsIiGX0TkIwHQYDVR0OBBYEFK24lFT/8MnwqCz4ol4xBO0N lfv9MD4GA1UdIAQ3MDUwMwYGZ4EMAQQBMCkwJwYIKwYBBQUHAgEWG2h0dHA6Ly93 d3cuZGlnaWNlcnQuY29tL0NQUzAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYI KwYBBQUHAwMwgbUGA1UdHwSBrTCBqjBToFGgT4ZNaHR0cDovL2NybDMuZGlnaWNl cnQuY29tL0RpZ2lDZXJ0VHJ1c3RlZEc0Q29kZVNpZ25pbmdSU0E0MDk2U0hBMzg0 MjAyMUNBMS5jcmwwU6BRoE+GTWh0dHA6Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9EaWdp Q2VydFRydXN0ZWRHNENvZGVTaWduaW5nUlNBNDA5NlNIQTM4NDIwMjFDQTEuY3Js MIGUBggrBgEFBQcBAQSBhzCBhDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGln aWNlcnQuY29tMFwGCCsGAQUFBzAChlBodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5j b20vRGlnaUNlcnRUcnVzdGVkRzRDb2RlU2lnbmluZ1JTQTQwOTZTSEEzODQyMDIx Q0ExLmNydDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4ICAQAgLKMeHbYCDN1S PJELMA/8BPtutmNup27jrc/5n9BGoXdrD6gJgKXJVYYsAVZpe+S3V0XDqi5N5PgR lw74Jr5IbPSQfrgWgL9hkMzBMoIT4R9YsAQ0lQFREgexuZhVnZXViWc7WwpSBs62 1j+kE3E7zhCFiibnXvMjgVuAXls6SlikGuvdD/Pex7ZECz3IsS7Pf6CbqYbznTTf 9dXIKGPyMoZDLGmedDvCQWeubqS1k9lUIv06knKZw6EY/LXENSb15kzrkF6/MfHE aGDpxUsLGL8DIK0kAjl2brwBWrhdVc6OPJp4SZXqjm9+/ZhC6dQQclVTb29BToug nN3IRBXtqHdXDkj0IEUYVuwLCx9P1IpMqOoXsDZp+CwCi6jy6jIflWpDv/5NRnZs iXKTbddsJLlrO21uNJusmhZcKFkq0prIoFuL6/yImG8DJ/UQGxISoGpfeURHI9JA V64jCRaJuydeeVENS6wm429WfgQ/fARxFg7YPRTwbHwurGQzHT/03Z2eiNgRnoi2 xmApiycAIEu1bOdBGYZ9nUHRuoVRnESYAiNCqW3c7DqIIRpPAoCSYsBx8mPWknX8 nXJHUFzFKDNH/j86tS43wmCgKPDW+zdarepfEmrg+lpUE3OhIHBnrB0qRxEU4N0Y fX7EDfCAv7velGAWDsLxrAPmCcoGhA== -----END CERTIFICATE-----Warning
You're responsible for securing your PowerShell script. Use a dedicated service account with the minimum required permissions. Don't use an admin or shared account. Script signing ensures integrity after deployment but doesn't guarantee source security.
Example
<################## .NAME bind-certificate .DESCRIPTION Consumes a certificate from the CAPI store to bind the certificate to a Windows service .PARAMETER certificateStore The Windows certificate store location where the certificate is stored .PARAMETER thumbprint The public key hash of the certificate .NOTES Successful script execution returns exit code 0. If the script fails, it returns a non-zero exit code, and Certificate Manager - SaaS displays the error message in the UI. ##################> function bind-certificate( [string]$certificateStore, [string]$thumbprint ) { return "Success" } -
In Script Path, enter the full path to the PowerShell script.
Tip
When you enable Installation Endpoint, the certificate is pushed to the script at this path when you save.
-
Optional: To create the certificate without pushing it to the Windows certificate store, set Push upon saving to No.
-
Select Save.
Want to schedule your provisions?
Schedule your provisions daily, weekly, or monthly. Learn more