Remove-SmbServerCertificateMapping

Removes a certificate mapping from the SMB server for SMB over QUIC.

Syntax

Remove-SmbServerCertificateMapping
      [-Name] <String[]>
      [[-Subject] <String[]>]
      [[-Thumbprint] <String[]>]
      [[-DisplayName] <String[]>]
      [[-StoreName] <String[]>]
      [[-Type] <Type[]>]
      [[-Flags]<Flags[]>]
      [[-RequireClientAuthentication] <Boolean[]>]
      [[-SkipClientCertificateAccessCheck] <Boolean[]>]
      [-IncludeHidden]
      [-Force]
      [-CimSession <CimSession[]>]
      [-ThrottleLimit <Int32>]
      [-AsJob]
      [-PassThru]
      [-WhatIf]
      [-Confirm]
      [<CommonParameters>]
Remove-SmbServerCertificateMapping
      -InputObject <CimInstance[]>
      [-Force]
      [-CimSession <CimSession[]>]
      [-ThrottleLimit <Int32>]
      [-AsJob]
      [-PassThru]
      [-WhatIf]
      [-Confirm]
      [<CommonParameters>]

Description

The Remove-SmbServerCertificateMapping cmdlet removes the certificates associated with the SMB server for SMB over QUIC. For more information, review SMB over QUIC.

Note

  • The RequireClientAuthentication and SkipClientCertificateAccessCheck parameters are only supported in Windows Server 2022 Datacenter: Azure Edition.

  • If the RequireClientAuthentication parameter is set to $true and SkipClientCertificateAccessCheck is set to $false, the server will perform both client certificate validation and access control checks.

  • If the RequireClientAuthentication parameter is set to $true and SkipClientCertificateAccessCheck is also set to $true, the server will perform client certificate validation but no access control checks.

Examples

Example 1 - Remove a certificate mapping for SMB server edge endpoint

$params = @{
    Name = "fs2.contoso.com"
    Thumbprint = "88032B3551FAF7DE26EFFFF814AA086E3DBD2A4F"
}
Remove-SmbServerCertificateMapping @params

Confirm
Are you sure you want to perform this action?
Performing operation 'Delete' on Target 'SMB Server Certificate Mapping.'.
[Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is "Y"): y

This command removes a certificate mapping for SMB server edge endpoint fs2.contoso.com with a specific certificate thumbprint.

Parameters

-AsJob

Runs the cmdlet as a background job. Use this parameter to run commands that take a long time to complete.

Type:SwitchParameter
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-CimSession

Runs the cmdlet in a remote session or on a remote computer. Enter a computer name or a session object, such as the output of a New-CimSession or Get-CimSession cmdlet. The default is the current session on the local computer.

Type:CimSession[]
Aliases:Session
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type:SwitchParameter
Aliases:cf
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-DisplayName

Specifies a friendly name to display for the mapping.

Type:String[]
Position:4
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-Flags

Specifies if Named Pipes are enabled for SMB over QUIC. The acceptable values for this parameter are:

  • None: Remove all flags.
  • AllowNamedPipe: Enable use of named pipes in SMB over QUIC connections for this mapping (off by default, overrides the value of the RestrictNamedpipeAccessOverQuic parameter).
  • DefaultCert: Not used.
Type:Flags[]
Accepted values:None, AllowNamedPipe, DefaultCert
Position:7
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-Force

Forces the command to run without asking for user confirmation.

Type:SwitchParameter
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-IncludeHidden

Not used.

Type:SwitchParameter
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-InputObject

Specifies the input object that's used in a pipeline command.

Type:CimInstance[]
Position:Named
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-Name

Specifies a fully-qualified DNS name or NetBIOS name that must match the certificate's subject name or an entry in the certificate's subject alternative names.

Type:String[]
Position:1
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-PassThru

Returns an object representing the item with which you're working. By default, this cmdlet doesn't generate any output.

Type:SwitchParameter
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-RequireClientAuthentication

Specifies whether client authentication is required for connections to the server. When this parameter is set to $true, clients must present a valid certificate to connect to the server. When it is set to $false, clients can connect without presenting a certificate.

Type:Boolean[]
Position:8
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-SkipClientCertificateAccessCheck

Specifies whether the server should skip the check for client certificate access when a client connects. This parameter only applies when the server certificate mapping RequireClientAuthentication value is $true. When this parameter is set to $true, the server will not perform the access control checks based on the client certificates. This can be useful in scenarios where the server is acting as a gateway or proxy and client certificate validation is sufficient.

However, it can also increase the risk of security breaches. When this parameter is set to $false, the server will perform the access control checks based on the client certificates in addition to the client certificate validation before allowing the client to connect.

Type:Boolean[]
Position:9
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-StoreName

Specifies the path to the certificate store for the certificate. The recommended value is "My" for the local machine personal store.

Type:String[]
Position:5
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-Subject

Specifies the subject name of the certificate.

Type:String[]
Position:2
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-ThrottleLimit

Specifies the maximum number of concurrent operations that can be established to run the cmdlet. If this parameter is omitted or a value of 0 is entered, then Windows PowerShell calculates an optimum throttle limit for the cmdlet based on the number of CIM cmdlets that are running on the computer. The throttle limit applies only to the current cmdlet, not to the session or to the computer.

Type:Int32
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-Thumbprint

Specifies the thumbprint value of the certificate.

Type:String[]
Position:3
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-Type

Specifies the type of certificate mapping. The acceptable value for this parameter is:

  • QUIC: Certificate mapping is for SMB over QUIC.
Type:Type[]
Accepted values:QUIC
Position:6
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet isn't run.

Type:SwitchParameter
Aliases:wi
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

Inputs

String[]

Microsoft.PowerShell.Cmdletization.GeneratedTypes.SmbServerCertificateMapping.Type[]

Microsoft.PowerShell.Cmdletization.GeneratedTypes.SmbServerCertificateMapping.Flags[]

Boolean[]

CimInstance[]

Outputs

CimInstance

CimInstance