Repository navigation
Document unguaranteed platform assumptions - #19
Merged
Merged
Conversation
Two behaviors the script depends on are conventional and widely observed but are not stated as guarantees in Microsoft published documentation: - A System.DirectoryServices.Protocols Kerberos bind uses the supplied NetworkCredential derived from -Credential rather than the calling thread identity. - System.DirectoryServices.ActiveDirectory.DirectoryServer.Name returns a fully qualified name, which the LDAP SPN and LDAPS certificate matching rely on. Add an Environment-validated assumptions section to docs/compatibility.md explaining both and how to confirm them, and add matching Not executed rows to the required live tests table in docs/validation.md. Regenerate CHECKSUMS.txt. Documentation only; no script or workflow changes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two platform behaviors the script relies on are conventional and widely observed, but are not stated as guarantees in Microsoft's published documentation. They were previously implicit:
System.DirectoryServices.ProtocolsKerberos bind uses the suppliedNetworkCredential(derived from-Credential) rather than the calling thread identity. Under OSD the thread identity is Local System, so if this did not hold, results would be attributable to the computer account instead of the supplied account.System.DirectoryServices.ActiveDirectory.DirectoryServer.Namereturns a fully qualified name. TheLDAP/<fqdn>service principal name and LDAPS certificate matching both depend on this.Changes (documentation only):
docs/compatibility.md— new## Environment-validated assumptionssection describing both assumptions, why each matters, and how to confirm them in your own environment, with a cross-link to the validation checklist.docs/validation.md— two rows appended to the## Required live teststable, both with statusNot executed.CHECKSUMS.txt— regenerated using the snippet indocs/release-process.md(two hash lines updated).No change to
Scripts/Add-ComputerToADGroup.ps1, workflows, manifests, or version. Publishedv1.0.0release assets remain byte-identical.Validation
build\Invoke-Validation.ps1passes on Windows PowerShell 5.1-SkipChecksums; manifest matches worktree and candidategit archiveCommand run on Windows PowerShell 5.1 after the edits:
Result:
Tests Passed: 227, Failed: 0, Skipped: 0, Inconclusive: 0, NotRun: 0—SHA-256 manifest verified against exact source bytes.—Validation passed.(exit code 0, 359.86s).The same gate was also run against the published
v1.0.0release ZIP after verifying its SHA-256 against both the.sha256sidecar and GitHub's published asset digest: 227/227 passed.No live Active Directory or ConfigMgr task sequence testing was executed. Both new assumptions are recorded in
docs/validation.mdasNot executed, consistent with the rest of that checklist.