Skip to content

Forward Artifact Signing correlation ID for PowerShell scripts - #41

Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
Devolutions:masterfrom
TimotheusBachinger:artifact-signing-correlation-id-scripts
Oct 6, 2026
Merged

Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
Devolutions:masterfrom
TimotheusBachinger:artifact-signing-correlation-id-scripts

Conversation

@TimotheusBachinger

Copy link
Copy Markdown
Contributor

Summary

  • Pass --artifact-signing-correlation-id (or the metadata CorrelationId)
    through the portable-core Artifact Signing provider, so the :sign
    request carries x-correlation-id / x-ms-correlation-id for PowerShell
    scripts (and MSIX/AppX) as it already does for PE, CAB and MSI.
  • Stop rejecting the correlation ID in native-shaped portable signing;
    signature-algorithm, api-version and authority overrides are still
    rejected there.

Callers use the correlation ID to attribute signing requests in the
Artifact Signing diagnostics. Previously, signing a .ps1 with it set
failed with "does not yet support correlation ID".

Verification

  • New test mode_portable_artifact_signing_forwards_correlation_id_for_scripts:
    psign-server --expect-correlation-id rejects the request without the
    header; fails before the change, passes after.
  • bash scripts/linux-portable-validation.sh
  • Signed a PE, an MSI and a .ps1 against a real Artifact Signing account
    from Linux: Get-AuthenticodeSignature reports Valid on Windows, and
    the service diagnostics show the correlation ID on all requests.

## Summary
- Pass `--artifact-signing-correlation-id` (or the metadata `CorrelationId`)
  through the portable-core Artifact Signing provider, so the `:sign`
  request carries `x-correlation-id` / `x-ms-correlation-id` for PowerShell
  scripts (and MSIX/AppX) as it already does for PE, CAB and MSI.
- Stop rejecting the correlation ID in native-shaped portable signing;
  signature-algorithm, api-version and authority overrides are still
  rejected there.

Callers use the correlation ID to attribute signing requests in the
Artifact Signing diagnostics. Previously, signing a `.ps1` with it set
failed with "does not yet support correlation ID".

## Verification
- New test `mode_portable_artifact_signing_forwards_correlation_id_for_scripts`:
  `psign-server --expect-correlation-id` rejects the request without the
  header; fails before the change, passes after.
- `bash scripts/linux-portable-validation.sh`
- Signed a PE, an MSI and a `.ps1` against a real Artifact Signing account
  from Linux: `Get-AuthenticodeSignature` reports `Valid` on Windows, and
  the service diagnostics show the correlation ID on all requests.
@TimotheusBachinger
Timotheus Bachinger (TimotheusBachinger) marked this pull request as ready for review September 30, 2026 08:59
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) merged commit 52366ea into Devolutions:master Oct 6, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants