{"id":54,"date":"2007-01-22T11:27:03","date_gmt":"2007-01-22T19:27:03","guid":{"rendered":"http:\/\/testblog.sapien.com\/index.php\/2007\/01\/22\/profiles-snapins-and-consoles\/"},"modified":"2007-01-22T11:27:03","modified_gmt":"2007-01-22T19:27:03","slug":"profiles-snapins-and-consoles","status":"publish","type":"post","link":"https:\/\/dev.sapien.com\/blog\/2007\/01\/22\/profiles-snapins-and-consoles\/","title":{"rendered":"Profiles, Snapins, and Consoles"},"content":{"rendered":"<p><P>We recently spent a lot of time around the office discussing profiles in Windows PowerShell. Actually, to be more specific, we were discussing snap-ins, those DLLs that bring new and wonderful cmdlets to your PowerShell environment.<\/P><P>There are three basic ways of getting a snapin loaded into PowerShell: By manually loading it (via Add-PSSnapin), by loading it your profile (by putting a call to Add-PSSnapin in the profile), or by manually loading it and then exporting a console (and then running that exported console in the future, rather than the default PowerShell shortcut). <\/P><P>The first way is obviously not great, as it&#8217;s very repetitive &#8211; you have to redo this each time PowerShell loads. The second method &#8211; the profile &#8211; isn&#8217;t repetitive. Neither is the third method.<\/P><P>All of this came out of a discussion on how to make PrimalScript provide code-hinting for added cmdlets, not just the core cmdlets. Technically, PrimalScript can do this already. However, PrimalScript actually hosts PowerShell itself &#8211; it doesn&#8217;t just run PowerShell as a command-line application. So, when PrimalScript loads up, it just gets the default PowerShell cmdlets &#8211; no snap-ins. Currently (and I&#8217;m talking about PrimalScript Enterprise and Pro, v4.1.532), PrimalScript doesn&#8217;t execute any profiles. If your scripts use any non-default cmdlets, then your script needs to explicitly load those via Add-PSSnapin. And, because the cmdlets aren&#8217;t present in the shell when PrimalScript starts, PrimalScript doesn&#8217;t &#8220;see&#8221; anything but the default cmdlets &#8211; which means no PrimalSense code-completion.<\/P><P>What will probably happen in some future version of PrimalScript is that it&#8217;ll give you the option of running your profiles when it loads up PowerShell. That way, any snapins added by your profile will be present when PrimalScript pulls a list of available cmdlets. That means any scripts you write will be able to use your snapins, and PrimalScript will be able to give you code-hinting and other PrimalSense help for those snapins. <\/P><P>However&#8230; there&#8217;s not a lot of guidance from Microsoft on how you&#8217;re <EM>supposed<\/EM> to add snapins. PrimalScript will exploit the profile technique because, practically, it&#8217;s the only thing it <EM>can<\/EM> do. However, if you&#8217;re decided to leave your profiles empty, and instead export a new PowerShell console shortcut whenever you add snap-ins&#8230; then PrimalScript will never &#8220;see&#8221; those snap-ins, and won&#8217;t be able to help with them. That&#8217;s because PrimalScript isn&#8217;t launching PowerShell.exe via&nbsp;a shortcut; it&#8217;s actually hosting the PowerShell DLL internally, just as PowerShell.exe itself does.<\/P><P><EM>Most<\/EM> non-Microsoft tools will have to utilize the profile technique of adding snap-ins. However, profiles have a downside: Although PowerShell can be configured to only run profile scripts which are digitally signed, we all know good and well that you&#8217;re going to set it to <EM>not<\/EM> require a signature. <STRONG>Bad Idea. <\/STRONG>Why? Because PS1 files are just text files: If you have a non-signed profile, then it&#8217;s possible for a malicious script or program to modify your profile. Next time you run PowerShell, malicious code <EM>that you didn&#8217;t even know existed<\/EM> would execute under your credentials. Had you signed the file, the malicious modification would have &#8220;broken&#8221; the signature, preventing the profile script from running and protecting you; this is a prime example of why profiles should <EM>always be signed<\/EM> and why PowerShell should only be configured to run <EM>signed<\/EM> scripts. <\/P><P>Because of the potential vulnerability of profiles, and because I know jolly well that everyone&#8217;s going to turn the digital signature security off, I&#8217;d prefer &#8211; from a security viewpoint &#8211; the console method of adding snap-ins. Sadly, <EM>that breaks <\/EM>what an editor like PrimalScript can work with.<\/P><P>The moral of the story? Use profiles to add snap-ins, but digitally sign them. Seriously &#8211; if you turn off and don&#8217;t use the digital signature security, you&#8217;ll eventually get what you&#8217;re asking for: Trouble.<\/P><P>&nbsp;<\/P><DIV class=wlWriterSmartContent id=0767317B-992E-4b12-91E0-4F059A8CECA8:77722b0a-ffbd-429a-ae13-def3481df745 contentEditable=false style=\"PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px\">Technorati tags: <A href=\"http:\/\/technorati.com\/tags\/powershell\" rel=tag>powershell<\/A>, <A href=\"http:\/\/technorati.com\/tags\/digital%20signature\" rel=tag>digital signature<\/A>, <A href=\"http:\/\/technorati.com\/tags\/profile\" rel=tag>profile<\/A>, <A href=\"http:\/\/technorati.com\/tags\/snapin\" rel=tag>snapin<\/A>, <A href=\"http:\/\/technorati.com\/tags\/add-pssnapin\" rel=tag>add-pssnapin<\/A>, <A href=\"http:\/\/technorati.com\/tags\/primalscript\" rel=tag>primalscript<\/A>, <A href=\"http:\/\/technorati.com\/tags\/cmdlets\" rel=tag>cmdlets<\/A><\/DIV><DIV class=wlWriterSmartContent id=0767317B-992E-4b12-91E0-4F059A8CECA8:2ec4c0a9-313d-4dfa-a172-fe7d1a00928d contentEditable=false style=\"PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px\">del.icio.us tags: <A href=\"http:\/\/del.icio.us\/popular\/powershell\" rel=tag>powershell<\/A>, <A href=\"http:\/\/del.icio.us\/popular\/digital%20signature\" rel=tag>digital signature<\/A>, <A href=\"http:\/\/del.icio.us\/popular\/profile\" rel=tag>profile<\/A>, <A href=\"http:\/\/del.icio.us\/popular\/snapin\" rel=tag>snapin<\/A>, <A href=\"http:\/\/del.icio.us\/popular\/add-pssnapin\" rel=tag>add-pssnapin<\/A>, <A href=\"http:\/\/del.icio.us\/popular\/primalscript\" rel=tag>primalscript<\/A>, <A href=\"http:\/\/del.icio.us\/popular\/cmdlets\" rel=tag>cmdlets<\/A><\/DIV><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently spent a lot of time around the office discussing profiles in Windows PowerShell. Actually, to be more specific, we were discussing snap-ins, those DLLs that bring new and wonderful cmdlets to your PowerShell environment.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[25],"tags":[],"class_list":["post-54","post","type-post","status-publish","format-standard","hentry","category-windows-powershell"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/54","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/comments?post=54"}],"version-history":[{"count":0,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/54\/revisions"}],"wp:attachment":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/media?parent=54"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/categories?post=54"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/tags?post=54"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}