/// <summary> /// Retrieves the attesttion policy for the specified <see cref="AttestationType"/>. /// </summary> /// <param name="certificateToRemove">The certificate to remove.</param> /// <param name="existingSigningKey">An existing key corresponding to the existing certificate.</param> /// <param name="existingSigningCertificate">An existing policy management certificates.</param> /// <param name="cancellationToken">Cancellation token used to cancel this operation.</param> /// <returns>An <see cref="AttestationResponse{PolicyCertificatesModificationResult}"/> with the policy for the specified attestation type.</returns> public virtual AttestationResponse <PolicyCertificatesModificationResult> RemovePolicyManagementCertificate( X509Certificate2 certificateToRemove, AsymmetricAlgorithm existingSigningKey, X509Certificate2 existingSigningCertificate, CancellationToken cancellationToken = default) { using DiagnosticScope scope = _clientDiagnostics.CreateScope($"{nameof(AttestationAdministrationClient)}.{nameof(RemovePolicyManagementCertificate)}"); scope.Start(); try { var tokenToRemove = new SecuredAttestationToken( new PolicyCertificateModification(certificateToRemove), existingSigningKey, existingSigningCertificate); var result = _policyManagementClient.Remove(tokenToRemove.ToString(), cancellationToken); var token = new AttestationToken(result.Value.Token); if (_options.ValidateAttestationTokens) { token.ValidateToken(GetSigners(), _options.ValidationCallback); } return(new AttestationResponse <PolicyCertificatesModificationResult>(result.GetRawResponse(), token)); } catch (Exception ex) { scope.Failed(ex); throw; } }
/// <summary> /// Retrieves the attesttion policy for the specified <see cref="AttestationType"/>. /// </summary> /// <param name="certificateToRemove">The certificate to remove.</param> /// <param name="existingSigningKey">An existing key corresponding to the existing certificate.</param> /// <param name="cancellationToken">Cancellation token used to cancel this operation.</param> /// <returns>An <see cref="AttestationResponse{PolicyCertificatesModificationResult}"/> with the policy for the specified attestation type.</returns> public virtual AttestationResponse <PolicyCertificatesModificationResult> RemovePolicyManagementCertificate( X509Certificate2 certificateToRemove, AttestationTokenSigningKey existingSigningKey, CancellationToken cancellationToken = default) { using DiagnosticScope scope = _clientDiagnostics.CreateScope($"{nameof(AttestationAdministrationClient)}.{nameof(RemovePolicyManagementCertificate)}"); scope.Start(); try { var tokenToRemove = new AttestationToken( BinaryData.FromObjectAsJson(new PolicyCertificateModification(certificateToRemove)), existingSigningKey); var result = _policyManagementClient.Remove(tokenToRemove.Serialize(), cancellationToken); var token = AttestationToken.Deserialize(result.Value.Token, _clientDiagnostics); if (_options.TokenOptions.ValidateToken) { var signers = GetSignersAsync(false, cancellationToken).EnsureCompleted(); if (!token.ValidateTokenInternal(_options.TokenOptions, signers, false, cancellationToken).EnsureCompleted()) { AttestationTokenValidationFailedException.ThrowFailure(signers, token); } } return(new AttestationResponse <PolicyCertificatesModificationResult>(result.GetRawResponse(), token)); } catch (Exception ex) { scope.Failed(ex); throw; } }