Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions CHECKSUMS.txt
Original file line number Diff line number Diff line change
Expand Up @@ -36,10 +36,9 @@
8946F63BA3FE8182DF6BFDB1DAEECAFDCD02677EFDDB9B15D98108379BA9748D Scripts/Add-ComputerToADGroup.ps1
8F8586B394762C5881C1220DF3959D967DF6AC375286D2F4F61EF551F2EB587D Tests/Runtime.Tests.ps1
99D0818971B014847E1EED2303AC76D88216B010E6B3D5E71E3411BBE670E909 AUTHORS.md
9C055B2E3DC677C2592FDD614B185E5C127E38F621972BACEDFD6D928AA1AD7B docs/validation.md
9C069DC1A798FD578D45295CE3CB502B39ED5693C7F282EE45646E396E563A21 assets/people-team.svg
9FE0500255FB65C0D2F5982E870FBB5B619480D0496BFF2FBAEBE28E67F05DEC docs/compatibility.md
A047D4BF5DC341B6E460F0D3EABD52AA884ED92F0EE5A2B86847B3AEB3486609 assets/folder-arrow-right.svg
A16476A9193E48D0FDCA1EBE182F0F6CA2EA68D34355B3AD35C619F24008C4E9 docs/validation.md
A6C22D28A2041CEF448BA7650FB84E61092314BB3850FCF5B58AA42E49A16160 examples/git-configuration.md
A996D56F8BC4CDC5AC325D5322EC6577014CCA28E89DCD6E654CBAE2C464970E assets/validation-pass.svg
AE0EBC700A81F090A59935F13672E9109DE6616D49E8FADC36003028DEB94202 docs/development.md
Expand All @@ -60,4 +59,5 @@ DF3A074261544800B739DEE93B071DE5383EFE796B874D7673AD69A5548F7A4A .github/FUNDIN
E49B0BAD89C4CAF2A07BB3FA625FF431977115A81A39B455061E96534BE291A0 .github/dependabot.yml
EA3E0EBA3F113DF27D462166E7065CD761167531E53ED031FE6B820E0C91AC60 assets/banner.svg
EFB5564544D49377DC1DACC2970D445FDCBC5E689DA7B4E5501267549622E2E2 .github/pull_request_template.md
F3DEABC14B566A687506BFC3079BB44F999A52A28E29741A8CC9777B6239D378 docs/compatibility.md
FD729F46D373707A9228AB503733014BA8DA4C6B36AFB38FA87FE369A6F3FCFA Tests/Repository.Tests.ps1
11 changes: 11 additions & 0 deletions docs/compatibility.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,3 +59,14 @@ If both compatibility options are needed, specify them together:
```

Validate each compatibility mode you intend to use; a successful default-mode test does not establish the others. See [security](../SECURITY.md) and the [environment-validation checklist](validation.md#required-live-tests).

## Environment-validated assumptions

Two platform behaviors the script relies on are conventional and widely observed, but are not stated as guarantees in Microsoft's published documentation. Confirm both in your own environment rather than assuming them.

| Assumption | Why it matters | How to confirm |
|---|---|---|
| A `System.DirectoryServices.Protocols` Kerberos bind uses the supplied `NetworkCredential` derived from the `PSCredential` rather than the calling thread identity | The script runs as Local System and depends on the explicit credential being used for the directory bind | Bind with a credential whose group permissions differ from the computer account and confirm the directory operation reflects the supplied account |
| `System.DirectoryServices.ActiveDirectory.DirectoryServer.Name` returns a fully qualified domain name | The value is used to build the `LDAP/<fqdn>` service principal name for Kerberos and for LDAPS certificate matching | Inspect the discovered controller names recorded in the log and confirm each is fully qualified in your forest and DNS configuration |

Both appear in the [environment-validation checklist](validation.md#required-live-tests). No live Active Directory verification of either assumption was executed for this release.
2 changes: 2 additions & 0 deletions docs/validation.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,5 +72,7 @@ Complete these checks in a controlled environment before broad rollout. **None w
| Sanitized ConfigMgr log | Not executed | Corresponding `smsts.log` entries contain no credentials or unintended parameter disclosure |
| Negotiate compatibility | Not executed | Explicit opt-in and enforced LM/NTLMv1 denial; negotiated authentication checked independently rather than inferred from `AuthType` |
| Credential cleanup and failure propagation | Not executed | Both hidden custom variables cleared on success/failure and failed script results preserved |
| Explicit credential honored by the directory bind | Not executed | A bind credential whose group permissions differ from the computer account produces directory results attributable to the supplied account rather than the Local System thread identity |
| Fully qualified domain controller names | Not executed | Discovered controller names recorded in the log are fully qualified, so the `LDAP/<fqdn>` service principal name and LDAPS certificate matching resolve correctly |

Keep raw logs private. Record only sanitized evidence and non-sensitive environment versions. See [compatibility](compatibility.md) for candidate platforms and [security](../SECURITY.md) for limitations.
Loading