Public/Uninstall-ADCSGoat.ps1

function Uninstall-ADCSGoat {
    <#
    .SYNOPSIS
        Removes an ADCSGoat deployment, restoring pre-change state ACL-last.

    .DESCRIPTION
        Drives the teardown contract settled in ADCSGoat issue #30 from the
        state file written at deploy time. Restores, in order: clone cns are
        removed from the selected CA's certificateTemplates (and the attribute
        returned to its pre-change member set), clone template objects and
        their companion OID objects are deleted, and finally the Enrollment
        Services security descriptor is restored byte-for-byte — reversing the
        ESC5 CA-object grant last. Any failure before the ACL step aborts and
        leaves the grant in place, reporting what remains.

        Performs no legacy detection; it restores only what the state file
        records.

    .PARAMETER StatePath
        Where the deploy state file lives. Defaults to ADCSGoat.State.xml next
        to the module root.

    .PARAMETER Server
        The domain controller to write to. Defaults to the logon server.

    .EXAMPLE
        Uninstall-ADCSGoat

        Tears down the deployment recorded in the default state file.
    #>

    [Diagnostics.CodeAnalysis.SuppressMessageAttribute('PSUseShouldProcessForStateChangingFunctions', '',
        Justification = 'State-driven restore; destructive steps ordered ACL-last so a failure never strands a partial access state.')]
    [CmdletBinding()]
    param (
        [Parameter()]
        [ValidateNotNullOrEmpty()]
        [string]$StatePath,

        [Parameter()]
        [ValidateNotNullOrEmpty()]
        [string]$Server
    )

    begin {
        if ([string]::IsNullOrEmpty($StatePath)) {
            $StatePath = Join-Path -Path $PSScriptRoot -ChildPath '..\ADCSGoat.State.xml'
        }
        $teardownParams = @{ StatePath = $StatePath }
        if ($PSBoundParameters.ContainsKey('Server')) { $teardownParams['Server'] = $Server }
    }

    process {
        Invoke-AGDeployTeardown @teardownParams
    }
}