{"id":782,"date":"2008-02-21T07:37:10","date_gmt":"2008-02-21T15:37:10","guid":{"rendered":"http:\/\/www.scriptinganswers.com\/essentials\/index.php\/2008\/02\/21\/how-do-i-sign-a-windows-powershell-script\/"},"modified":"2008-11-04T09:15:14","modified_gmt":"2008-11-04T17:15:14","slug":"how-do-i-sign-a-windows-powershell-script-2","status":"publish","type":"post","link":"https:\/\/dev.sapien.com\/blog\/2008\/02\/21\/how-do-i-sign-a-windows-powershell-script-2\/","title":{"rendered":"How do I sign a Windows PowerShell script?"},"content":{"rendered":"<p>First you&#8217;ll need a code-signing certificate. If you purchase one, you&#8217;ll be looking for a &#8220;Class III&#8221; digital certificate of the &#8220;Microsoft Authenticode&#8221; variety. This will often come in two parts: An SPC file, which is the Software Publishing Certificate, and a PVK file, which is the corresponding private key. If you use a utility like MakeCert.exe (which is included in the Windows Platform SDK), you can produce a certificate in a CER file; you&#8217;ll need to use the Cert2spc.exe utility (also in the SDK) to convert that to an SPC\/PVK file pair.<\/p>\n<p>Next you have to either install the certificate or make it into a PFX file, which includes both halves of the key. I prefer the PFX approach, since you can use the Pvk2Pfx.exe utility (again in the SDK) to combine your SPC file and your PVK file into a password-protected PFX file.<\/p>\n<p>Whew. You only have to do all that nonsense once, thank goodness.<\/p>\n<p>When you&#8217;re ready to sign, run this in the shell:<\/p>\n<p>Set-AuthenticodeSignature MyScript.ps1 -cert (Get-PFXCertificate MyCert.pfx)<\/p>\n<p>You&#8217;ll be prompted for a password as the certificate loads, and a signature will be applied to the designated script.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>First you&#8217;ll need a code-signing certificate. If you purchase one, you&#8217;ll be looking for a &#8220;Class III&#8221; digital certificate of the &#8220;Microsoft Authenticode&#8221; variety. This will often come in two parts: An SPC file, which is the Software Publishing Certificate, and a PVK file, which is the corresponding private key. If you use a utility [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[283,25],"tags":[344,92,375,28,91,93],"class_list":["post-782","post","type-post","status-publish","format-standard","hentry","category-howto","category-windows-powershell","tag-authenticode","tag-certificate","tag-pfx","tag-powershell","tag-sign","tag-signature"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/comments?post=782"}],"version-history":[{"count":1,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/782\/revisions"}],"predecessor-version":[{"id":834,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/782\/revisions\/834"}],"wp:attachment":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/media?parent=782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/categories?post=782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/tags?post=782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}