From 34c3de35707f28ed5f3fbbf00220d6d64a39beb0 Mon Sep 17 00:00:00 2001 From: Claudio Mendes Date: Tue, 6 Oct 2026 21:01:09 +0200 Subject: [PATCH] Document unguaranteed platform assumptions Two behaviors the script depends on are conventional and widely observed but are not stated as guarantees in Microsoft published documentation: - A System.DirectoryServices.Protocols Kerberos bind uses the supplied NetworkCredential derived from -Credential rather than the calling thread identity. - System.DirectoryServices.ActiveDirectory.DirectoryServer.Name returns a fully qualified name, which the LDAP SPN and LDAPS certificate matching rely on. Add an Environment-validated assumptions section to docs/compatibility.md explaining both and how to confirm them, and add matching Not executed rows to the required live tests table in docs/validation.md. Regenerate CHECKSUMS.txt. Documentation only; no script or workflow changes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- CHECKSUMS.txt | 4 ++-- docs/compatibility.md | 11 +++++++++++ docs/validation.md | 2 ++ 3 files changed, 15 insertions(+), 2 deletions(-) diff --git a/CHECKSUMS.txt b/CHECKSUMS.txt index 5a405f9..675ebb6 100644 --- a/CHECKSUMS.txt +++ b/CHECKSUMS.txt @@ -36,10 +36,9 @@ 8946F63BA3FE8182DF6BFDB1DAEECAFDCD02677EFDDB9B15D98108379BA9748D Scripts/Add-ComputerToADGroup.ps1 8F8586B394762C5881C1220DF3959D967DF6AC375286D2F4F61EF551F2EB587D Tests/Runtime.Tests.ps1 99D0818971B014847E1EED2303AC76D88216B010E6B3D5E71E3411BBE670E909 AUTHORS.md -9C055B2E3DC677C2592FDD614B185E5C127E38F621972BACEDFD6D928AA1AD7B docs/validation.md 9C069DC1A798FD578D45295CE3CB502B39ED5693C7F282EE45646E396E563A21 assets/people-team.svg -9FE0500255FB65C0D2F5982E870FBB5B619480D0496BFF2FBAEBE28E67F05DEC docs/compatibility.md A047D4BF5DC341B6E460F0D3EABD52AA884ED92F0EE5A2B86847B3AEB3486609 assets/folder-arrow-right.svg +A16476A9193E48D0FDCA1EBE182F0F6CA2EA68D34355B3AD35C619F24008C4E9 docs/validation.md A6C22D28A2041CEF448BA7650FB84E61092314BB3850FCF5B58AA42E49A16160 examples/git-configuration.md A996D56F8BC4CDC5AC325D5322EC6577014CCA28E89DCD6E654CBAE2C464970E assets/validation-pass.svg AE0EBC700A81F090A59935F13672E9109DE6616D49E8FADC36003028DEB94202 docs/development.md @@ -60,4 +59,5 @@ DF3A074261544800B739DEE93B071DE5383EFE796B874D7673AD69A5548F7A4A .github/FUNDIN E49B0BAD89C4CAF2A07BB3FA625FF431977115A81A39B455061E96534BE291A0 .github/dependabot.yml EA3E0EBA3F113DF27D462166E7065CD761167531E53ED031FE6B820E0C91AC60 assets/banner.svg EFB5564544D49377DC1DACC2970D445FDCBC5E689DA7B4E5501267549622E2E2 .github/pull_request_template.md +F3DEABC14B566A687506BFC3079BB44F999A52A28E29741A8CC9777B6239D378 docs/compatibility.md FD729F46D373707A9228AB503733014BA8DA4C6B36AFB38FA87FE369A6F3FCFA Tests/Repository.Tests.ps1 diff --git a/docs/compatibility.md b/docs/compatibility.md index c8c7b41..b59a28f 100644 --- a/docs/compatibility.md +++ b/docs/compatibility.md @@ -59,3 +59,14 @@ If both compatibility options are needed, specify them together: ``` Validate each compatibility mode you intend to use; a successful default-mode test does not establish the others. See [security](../SECURITY.md) and the [environment-validation checklist](validation.md#required-live-tests). + +## Environment-validated assumptions + +Two platform behaviors the script relies on are conventional and widely observed, but are not stated as guarantees in Microsoft's published documentation. Confirm both in your own environment rather than assuming them. + +| Assumption | Why it matters | How to confirm | +|---|---|---| +| A `System.DirectoryServices.Protocols` Kerberos bind uses the supplied `NetworkCredential` derived from the `PSCredential` rather than the calling thread identity | The script runs as Local System and depends on the explicit credential being used for the directory bind | Bind with a credential whose group permissions differ from the computer account and confirm the directory operation reflects the supplied account | +| `System.DirectoryServices.ActiveDirectory.DirectoryServer.Name` returns a fully qualified domain name | The value is used to build the `LDAP/` service principal name for Kerberos and for LDAPS certificate matching | Inspect the discovered controller names recorded in the log and confirm each is fully qualified in your forest and DNS configuration | + +Both appear in the [environment-validation checklist](validation.md#required-live-tests). No live Active Directory verification of either assumption was executed for this release. diff --git a/docs/validation.md b/docs/validation.md index eeb5737..194d88c 100644 --- a/docs/validation.md +++ b/docs/validation.md @@ -72,5 +72,7 @@ Complete these checks in a controlled environment before broad rollout. **None w | Sanitized ConfigMgr log | Not executed | Corresponding `smsts.log` entries contain no credentials or unintended parameter disclosure | | Negotiate compatibility | Not executed | Explicit opt-in and enforced LM/NTLMv1 denial; negotiated authentication checked independently rather than inferred from `AuthType` | | Credential cleanup and failure propagation | Not executed | Both hidden custom variables cleared on success/failure and failed script results preserved | +| Explicit credential honored by the directory bind | Not executed | A bind credential whose group permissions differ from the computer account produces directory results attributable to the supplied account rather than the Local System thread identity | +| Fully qualified domain controller names | Not executed | Discovered controller names recorded in the log are fully qualified, so the `LDAP/` service principal name and LDAPS certificate matching resolve correctly | Keep raw logs private. Record only sanitized evidence and non-sensitive environment versions. See [compatibility](compatibility.md) for candidate platforms and [security](../SECURITY.md) for limitations.