Sign in

Jordan Borean

@jborean.bsky.social
260 followers 58 following 376 posts
PostsRepliesMedia
Jordan Borean @jborean.bsky.social · 06/10/2026
A greek coin you gave to Charon to ferry you to the underworld. Fit into the whole Kerberos/Cerberus and was a short word :)
120
Jordan Borean @jborean.bsky.social · 06/10/2026
I've always disliked that I couldn't test Kerberos in CI easily and so I've written a #PowerShell module called Obol that can setup a KDC and configure the environment for the platform you are on github.com/jborean93/Po.... Uses @syfuhs.net's Kerberos.NET for the message parsing and encryption work.
194
Jordan Borean @jborean.bsky.social · 30/09/2026
Just had a play around tonight and it's a no. There's a few smaller issues that look to be trivial but the biggest blocker is the krb5.conf parser which heavily relies on reflection. Most likely more on other platforms plus adding a net8.0 target so it can mark itself as AOT compatible
100
Jordan Borean @jborean.bsky.social · 30/09/2026
@syfuhs.net are you aware if Kerberos.NET is Native AOT compatible? Do you know if there are/were blockers to supporting it or it’s just not tested/tried?
100
Jordan Borean @jborean.bsky.social · 30/09/2026
Any #WinRM users out there on Linux/macOS that use #PowerShell. I've been busy trying to get the v3 release of my module ready to go but this is a massive shift from how it used to work. Would love to get some real world testing to identify issues before I release it. github.com/jborean93/PS...
github.com
GitHub - jborean93/PSWSMan
Contribute to jborean93/PSWSMan development by creating an account on GitHub.
034
Jordan Borean @jborean.bsky.social · 25/09/2026
TLDR: .NET Framework vs .NET and it not being 100% compatible. They have announced that they are hoping to ship 7.x in box with the next Windows Server release and hopefully Win 11 follows along. Probably will still be side by side for the near future.
050
Jordan Borean @jborean.bsky.social · 24/09/2026
Definitely fair, ultimately I think in today’s world even getting access to your normal user environment is mostly game over. Still MS themselves need to follow their security boundaries.
000
Jordan Borean @jborean.bsky.social · 24/09/2026
In WT's defence doing this exposes a window that a non-admin user could type into to run things as admin. I get that for some people they don't care about this but if Microsoft shipped a feature like this it would be DoA with the security reports.
100
Jordan Borean @jborean.bsky.social · 18/08/2026
I haven't written it yet, just seeing if I would be wasting my time if I couldn't use it in the first place :)
010
Jordan Borean @jborean.bsky.social · 18/08/2026
@awakecoding.com have you ever looked at building an ssh forwarder dynamic channel for RDP in RDM? I'm interesting in doing so but I don't know if RDM can utilise custom plugins or if that's not possible.
100
Jordan Borean @jborean.bsky.social · 12/08/2026
> X25519 You got my hopes up for a minute in thinking it was ed25519. Still nice to see these new additions and improvements.
000
Jordan Borean @jborean.bsky.social · 11/08/2026
Please talk about it some more, love the .NET ecosystem and the System.Formats.Asn1 has been one of my favourite APIs around ASN.1. That being said I hate ASN.1 and the numerous "string" classes, so annoying having to remember what is what and then inevitably get it wrong anyway.
000
Jordan Borean @jborean.bsky.social · 07/08/2026
That way even if the end user can access that host keytab, it's extremely limited in what it can do outside of armouring their own AS-REQ.
000
Jordan Borean @jborean.bsky.social · 07/08/2026
Thanks! I think in the long run adding support for a custom store like armor_kt to gss_acquire_cred_from for GSSAPI to use internally. Then gssproxy could be used to protect the host keytab from end users. But as a stopgap a dedicated princ with little to no privileges just for armouring may be ok.
100
Jordan Borean @jborean.bsky.social · 07/08/2026
Thanks, it's been a while since I tested but wouldn't there need to be some check to allow such a principal to get their TGT without armouring in the first place? E.g. amouring is enforced by the KDC but either for or not for x?
100
Jordan Borean @jborean.bsky.social · 07/08/2026
I'm wondering if it is possible to create a single use principal specifically for armouring purposes so that even if their keytab is readable by users on the Linux host, they won't be able to do anything with that keytab aside from using it for amouring.
110
Jordan Borean @jborean.bsky.social · 07/08/2026
@syfuhs.net I'm once again looking at FAST/armouring support from Linux and one of the biggest hiccups is the lack of a privileged broker to protect the machine keytab armouring the users TGT. What are the requirements for a principal that can be used for armouring, e.g. specific objectClass, SPN?
120
Jordan Borean @jborean.bsky.social · 02/08/2026
It’s not as clear cut, it can be faster but not in all scenarios. Once arrays get even larger then .Add() is still faster and .Add() is faster on non-Windows anyway. The best thing to do is just capture the output but in any case += or .Add() are going to be fine for 99 out of 100 cases.
000
Jordan Borean @jborean.bsky.social · 30/07/2026
Ah ok I misread what you were saying. I thought you were saying you were creating the whole PowerShell engine/SDK in NAOT and doing something special with the runtime and was confused.
110
Jordan Borean @jborean.bsky.social · 29/07/2026
What benefits do you see NAOT gives you when it comes to PowerShell? You still need to ship the whole runtime + extra assemblies so you can't really trim it, you potentially loose things like stacktraces or at least make it a bit more obscure by turning it into native code, more complex builds, etc
100
Jordan Borean @jborean.bsky.social · 28/07/2026
Sorry I was misremembering which ones, it wasn't the Appx cmdlets it was the DISM based ones like Get-AppxProvisionedPackage and Get-WindowsOptionalFeature. Still can you explain that problem in the GitHub link I am having in winget when trying to use it in a non-interactive session like SSH?
Top console Window with MSIX installed PowerShell failing to run DISM based cmdlets Get-AppxProvisionedPackage -Online and Get-WindowsOptionalFeature -Online with the error "Class not registered". Bottom console MSI installed PowerShell that successfully ran Get-AppxProvisionedPackage -Online and showing the results.
100
Jordan Borean @jborean.bsky.social · 17/07/2026
Not sure if it’s related to winget being run as an msix packaged application like how PowerShell can’t run the Appx cmdlets if it was installed as an msix package. Also just wanted to say I appreciate those blog posts you’ve been doing on MSIX!
100
Jordan Borean @jborean.bsky.social · 17/07/2026
@drustheaxe.bsky.social just wondering if you had any idea as to why winget might be “failing” to add their sources msix causing this problem github.com/microsoft/wi...? It weirdly doesn’t fail but the add does not work. Same API in the same user context works to do this but not within winget.
github.com
Failing to add WinGet Source in non-interactive session · Issue #6334 · microsoft/winget-cli
Relevant area(s) WinGet CLI Relevant command(s) winget list Brief description of your issue When running winget in a non-interactive session, like ssh/winrm, any operations that need to setup the w...
100
Jordan Borean @jborean.bsky.social · 15/07/2026
Then you'll top it off with the best movie in the series Jurassic World Dominion right?
000
Jordan Borean @jborean.bsky.social · 09/07/2026
Should have just gone the old define it as Invoke-ShouldBe and create an alias for Should-Be. No reflection or private APIs needed and no warning.
110
Jordan Borean @jborean.bsky.social · 30/06/2026
Unfortunately there's no easy way except to just reimplement the Runspace handling manually. There are some modules like www.powershellgallery.com/packages/Mic... which you could potentially bundle to provide an easier API to manage it all in.
powershellgallery.com
Microsoft.PowerShell.ThreadJob 2.2.0
PowerShell's built-in BackgroundJob jobs (Start-Job) are run in separate processes on the local machine. They provide excellent isolation but are resource heavy. Running hundreds of BackgroundJob job...
010
Jordan Borean @jborean.bsky.social · 29/06/2026
Nice, I think this is the better way of doing this. The pipeline still acts like normal but a hint is provided to explain why and what to do for this other common scenario.
030
Jordan Borean @jborean.bsky.social · 29/06/2026
I’ll give you a year just to be optimistic
000
Jordan Borean @jborean.bsky.social · 29/06/2026
Just in time for Pester 6 :)
100
Jordan Borean @jborean.bsky.social · 24/06/2026
It sounds like this is the predictor listing which uses your command history learn.microsoft.com/en-us/powers... and not context specific tab completion. The predictor listing is the grey text you see (default behaviour) that is selected by pressing the right arrow key while tab completion uses tab
learn.microsoft.com
Using predictors in PSReadLine - PowerShell
This article describes the features and usage of Predictive IntelliSense in PSReadLine.
000
Reposted by Jordan Borean
nohwnd @jakubjares.com · 02/06/2026
Delivered a good talk on #pspester mocking internals, souurce code soon thanks, for the photos. Come join the Pester follow along tomorrow, it is called advanced, but is teaching good mix of stuff. #psconf #psconfeu #powershell I
0124
Jordan Borean @jborean.bsky.social · 26/05/2026
That AI money be crazy
030
Jordan Borean @jborean.bsky.social · 21/05/2026
As this temp list had no pre set capacity it’s internal array had to be resized and the existing elements copied everytime a power of 2 items were added. Making it hideously inefficient. 7.5 fixed this so now it only pays the resize and copy tax which isn’t as bad
010
Jordan Borean @jborean.bsky.social · 21/05/2026
Fun thing is that this wasn’t the full problem (but was assumed to be). Before 7.5 it was not only doing this it was using an intermediate list with no preset capacity and adding each item to that list one by one before returning the array with the new element…
110
Jordan Borean @jborean.bsky.social · 13/05/2026
People still use 5.1 /s I get what you mean though I find it annoying and sometimes do `$objThatMayBeNull | ForEach-Object Dispose` a lot but it kill me inside. After working with C# more I find null being more annoying and love the nullable reference types but I get pwsh is in a different field
030
Jordan Borean @jborean.bsky.social · 12/05/2026
$obj.Trim() for it to not allow null and ${obj}?.Trim() to allow null. You can have it both ways :)
null.you
120
Jordan Borean @jborean.bsky.social · 11/05/2026
The reason I say this is that MakeAppx pack /? shows the /pb option that says "Publisher bridging is useful when the new issued cert subject name change ...". The link here also only has an option to specify the subject CN and nothing to do with the certificate itself.
010
Jordan Borean @jborean.bsky.social · 11/05/2026
I could be wrong but I'm 75% sure that the persistent identity is for when the certificate subject changes and not the certificate itself. For Azure TS the subject stays consistent and is part of your identity validation so you shouldn't have to do this.
110
Jordan Borean @jborean.bsky.social · 07/05/2026
I would triple check but I definitely just generated a new self signed cert with a subject that matched the Publisher in the manifest and used that with signtool.exe when testing what it changes to the zip structure the other day.
010
Jordan Borean @jborean.bsky.social · 07/05/2026
It should just work, did you try it and had an error?
100
Reposted by Jordan Borean
Marc-André Moreau @awakecoding.com · 06/05/2026
New blog post series! 📰 Everything wrong with MSIX, starting with how it cannot be used in a system context, such as system services. This affects WinGet, PowerShell, and a lot of other software 👇💻 awakecoding.com/posts/everyt...
awakecoding.com
Everything Wrong with MSIX: No System Context
PowerShell's MSI deprecation exposes the problem with treating MSIX like a better MSI: user-registered packages can disappear from SYSTEM, breaking services, scheduled tasks, remoting, and automation.
1102
Jordan Borean @jborean.bsky.social · 05/05/2026
I would love to be proven wrong but either there is a lack of tooling, docs, or just scenarios that MSIX cannot address. I also find it concerning that the APPX/MSIX cmdlets in pwsh are broken if you are using pwsh installed through the MSIX/Store
210
Jordan Borean @jborean.bsky.social · 05/05/2026
… using it as a scheduled task action exec for any user rather than a user it needs to be staged for first. Then there’s the PSRemoting subsystem. Maybe there is an API I’m missing but the wording from MS mostly stems from you are wrong then on the other hand they say it has limitations.
140
Jordan Borean @jborean.bsky.social · 05/05/2026
The thing that trips up is the lack of an install system wide option. I get that you can provision a package but that only affects new users, to install for existing users it seems like you need to add/register per user. That’s also ignoring the issues around a machine context like …
230
Jordan Borean @jborean.bsky.social · 22/04/2026
function true { $true } function test { return true } test # True You can have it both ways :)
120
Jordan Borean @jborean.bsky.social · 22/04/2026
It's ultimately different parsing modes, you have the argument mode (parts after a cmd) to make it easier for calling exe's and functions like a normal shell vs expression mode. The latter is looser in what it accepts and treats more things as literals. learn.microsoft.com/en-us/powers...
learn.microsoft.com
about_Parsing - PowerShell
Describes how PowerShell parses commands.
020
Jordan Borean @jborean.bsky.social · 21/04/2026
It's not really a document but this is what we use in CI to test out installing/managing an appx/msix package github.com/ansible-coll.... It creates a self signed cert but you can swap that with any code signing cert you have
github.com
ansible.windows/tests/integration/targets/win_package/library/win_make_appx.ps1 at main · ansible-collections/ansible.windows
Windows core collection for Ansible. Contribute to ansible-collections/ansible.windows development by creating an account on GitHub.
020
Jordan Borean @jborean.bsky.social · 15/04/2026
Just say you have a chance to win a PS5 like @hcritter.bsky.social competition has. Give them a cd with the PS5 installer on it.
140
Jordan Borean @jborean.bsky.social · 11/04/2026
They've been modernising every release with 7.5 with each one causing regressions in the build outputs, delaying of the release timeframe, and wasting of the teams resources so they can no longer deal with issues and prs. Seems like it's a never ending story and now 7.7 will have this new problem...
000
Jordan Borean @jborean.bsky.social · 11/04/2026
It's alright, they've now got a year to waste trying to update their build process (for the 3rd time) and deal with the fallout/breakages there. Meanwhile PRs/Issues continue to pile on and community users get frustrated by the lack of any new features while internal problems are sorted.
110