0
votes

I have an UBUNTU 16.04 box (Let's call it EARTH) and Windows 2012 R2 box (Let's call it MARS). Using the below commands from the Windows box (MARS) I'm generating a self signed cert that I'm planning to use for PS Remoting.

CMD1: $Cert = New-SelfSignedCertificate -CertstoreLocation Cert:\LocalMachine\My -DnsName "myHost"

CMD2: Export-Certificate -Cert $Cert -FilePath C:\temp\cert

On MARS (Windows box) there is a WSMAN listener created using the thumbprint of the self sign certificated that was just created.

CMD3: New-Item -Path WSMan:\LocalHost\Listener -Transport HTTPS -Address * -CertificateThumbPrint $Cert.Thumbprint –Force

I'm trying to initiate a PowerShell Remoting session from EARTH (UBUNTU box) to MARS

Does anyone know how to import the certificate into EARTH (UBUNTU server) so powershell can use it for the remoting session?

Source of PS Session: EARTH, the UBUNTU server

Target of PS Session: MARS, the windows 2012 R2 box from which the certificate was generated.

EARTH (UBUNTU server) is running PowerShell version 6.1 preview.2

Thank you for your help in advance!

1

1 Answers

0
votes

The export / Import certificate cmdlets are the targets for this use case. As for Ubuntu, just use the cmdline on Ubuntu, see the Ubuntu forum discussion:

In ubuntu:

    • Go to /usr/local/share/ca-certificates/
    • Create a new folder, i.e. "sudo mkdir school"
    • Copy the .crt file into the school folder
    • Make sure the permissions are OK (755 for the folder, 644 for the file)
    • Run "sudo update-ca-certificates"

https://askubuntu.com/questions/645818/how-to-install-certificates-for-command-line

Or the help info from Ubuntu directly.

Installing the Certificate

You can install the key file server.key and certificate file server.crt, or the certificate file issued by your CA, by running following commands at a terminal prompt:

sudo cp server.crt /etc/ssl/certs
sudo cp server.key /etc/ssl/private

Now simply configure any applications, with the ability to use public-key cryptography, to use the certificate and key files. For example, Apache can provide HTTPS, Dovecot can provide IMAPS and POP3S, etc.

https://help.ubuntu.com/lts/serverguide/certificates-and-security.html

MS has provided step-by-step guidance on how to set this up and use it. Specifically the below directly addresses Ubuntu. This allows remoting without the additional certificate step you are using.

PowerShell Remoting Over SSH

Setup on Windows Machine

  1. Install the latest PowerShell for Windows build from GitHub ◦You can tell if it has the SSH remoting support by looking at the parameter sets for New-PSSession
Get-Command New-PSSession -syntax
New-PSSession [-Name <string[]>] [-HostName <string>] [-UserName <string>] [-KeyPath <string>] [<CommonParameters>]
  1. Install the latest Win32 Open SSH build from GitHub using the installation instructions
  2. Edit the sshd_config file at the location where you installed Win32 Open SSH ◦Make sure password authentication is enabled ◾PasswordAuthentication yes

◦Add a PowerShell subsystem entry
◾Subsystem powershell

PowerShell_Install_Path\powershell.exe -sshs -NoLogo -NoProfile

◦Optionally enable key authentication
◾RSAAuthentication yes ◾PubkeyAuthentication yes

4.Restart the sshd service ◦Restart-Service sshd

Setup on Linux (Ubuntu 14.04) Machine:

1.Install the latest PowerShell for Linux build from GitHub ◦You can tell if it has the SSH remoting support by looking at the parameter sets for New-PSSession

Get-Command New-PSSession -syntax New-PSSession [-Name ] [-HostName ] [-UserName ] [-KeyPath ] []

2.Install Ubuntu SSH as needed ◦sudo apt install openssh-client

sudo apt install openssh-server

3.Edit the sshd_config file at location /etc/ssh ◦Make sure password authentication is enabled ◾PasswordAuthentication yes

◦Add a PowerShell subsystem entry
◾Subsystem powershell powershell -sshs -NoLogo -NoProfile

◦Optionally enable key authentication
◾RSAAuthentication yes ◾PubkeyAuthentication yes

4.Restart the sshd service ◦sudo service ssh restart

PowerShell Remoting Example:

The easiest way to test remoting is to just try it on a single machine. Here I will create a remote session back to the same machine on a Linux box. Notice that I am using PowerShell cmdlets from a command prompt so we see prompts from ssh asking to verify the host computer as well as password prompts. You can do the same thing on a Windows machine to ensure remoting is working there and then remote between machines by simply changing the host name.

Linux to Linux

PS /home/TestUser> $session = New-PSSession -HostName UbuntuVM1 -UserName TestUser

The authenticity of host 'UbuntuVM1 (9.129.17.107)' cannot be established.

ECDSA key fingerprint is SHA256:2kCbnhT2dUE6WCGgVJ8Hyfu1z2wE4lifaJXLO7QJy0Y.

Are you sure you want to continue connecting (yes/no)?

TestUser@UbuntuVM1s password:

PS /home/TestUser> $session

 Id Name            ComputerName    ComputerType    State         ConfigurationName     Availability
 -- ----            ------------    ------------    -----         -----------------     ------------
  1 SSH1            UbuntuVM1       RemoteMachine   Opened        DefaultShell             Available

https://github.com/PowerShell/PowerShell/blob/866b558771a20cca3daa47f300e830b31a24ee95/docs/new-features/remoting-over-ssh/README.md