Public/Import-PWSHYBKPIVKey.ps1

function Import-PWSHYBKPIVKey {
    <#
    .SYNOPSIS
        Imports a private key into a PIV slot of a locally attached YubiKey.
    .DESCRIPTION
        Wraps "yubico-piv-tool.exe --action import-key". Overwrites any key already present in
        the target slot with no way to recover it, so this cmdlet supports -WhatIf/-Confirm with
        ConfirmImpact 'High'. Throws on failure rather than returning a value, matching Import-
        verb convention.

        Accepts the "import-key" action's config-declared options (-Slot, -Input, -KeyFormat,
        -Password, -ManagementKey, -PinPolicy, -TouchPolicy, -Reader) as dynamic parameters built
        from Config\Posh-YBKPIV.json.
    .PARAMETER Slot
        The PIV slot to import the key into, e.g. '9a'.
    .PARAMETER Input
        Path to the key file to import.
    .PARAMETER KeyFormat
        File format of the key: PEM, PKCS12, GZIP, DER, or SSH. Defaults to PEM when omitted.
    .PARAMETER Password
        Password protecting the input file (e.g. a PKCS#12 bundle), as a SecureString.
    .PARAMETER ManagementKey
        The management key authorizing the operation, as a SecureString. Defaults to
        yubico-piv-tool.exe's built-in default management key when omitted.
    .PARAMETER PinPolicy
        PIN policy to apply to the imported key: never, once, always, matchonce, or matchalways.
    .PARAMETER TouchPolicy
        Touch policy to apply to the imported key: never, always, or cached.
    .PARAMETER Reader
        Name of the smart card reader to target, when more than one is attached. If omitted,
        yubico-piv-tool.exe uses its own default reader selection.
    .INPUTS
        None. This cmdlet does not accept pipeline input.
    .OUTPUTS
        None. Throws a terminating error on failure; produces no output on success.
    .NOTES
        -Slot, -Input, -KeyFormat, -Password, -ManagementKey, -PinPolicy, -TouchPolicy, and
        -Reader are declared dynamically from Config\Posh-YBKPIV.json and therefore do not appear
        in Get-Help's PARAMETERS/SYNTAX sections. Run `Get-Command Import-PWSHYBKPIVKey -Syntax`
        for the authoritative, current parameter list.
    .EXAMPLE
        Import-PWSHYBKPIVKey -Slot '9a' -Input 'C:\keys\key.pem'
        Imports the key from key.pem into slot 9a after confirmation.
    .LINK
        https://developers.yubico.com/yubico-piv-tool/Actions/
    .LINK
        New-PWSHYBKPIVKey
    .LINK
        Remove-PWSHYBKPIVKey
    #>

    [CmdletBinding(SupportsShouldProcess, ConfirmImpact = 'High')]
    param()

    DynamicParam {
        $dynamicConfig = Read-PWSHYBKPIVConfigFile
        Get-PWSHYBKPIVActionParameter -Action 'import-key' -CmdletWrapping $dynamicConfig.cmdletWrapping
    }

    begin {
        $config = Read-PWSHYBKPIVConfigFile
        Write-PWSHYBKPIVLog -Config $config -Level Debug -CmdletName $MyInvocation.MyCommand.Name `
            -Message 'Cmdlet invoked' -BoundParameters $PSBoundParameters

        $architecture = Resolve-PWSHYBKPIVArchitecture -Architecture $config.installation.architecture
        $exePath = Get-PWSHYBKPIVInstallPath -Installation $config.installation -Architecture $architecture
        if (-not (Test-Path -Path $exePath -PathType Leaf)) {
            throw "yubico-piv-tool.exe was not found at '$exePath'. Run Install-PWSHYBKPIVTool first."
        }
    }

    end {
        $slotDescription = "PIV slot $($PSBoundParameters['Slot'])"
        if (-not $PSCmdlet.ShouldProcess($slotDescription, 'Import key')) {
            return
        }

        try {
            $null = Invoke-PWSHYBKPIVTool -ExePath $exePath -Action 'import-key' `
                -CmdletWrapping $config.cmdletWrapping -BoundParameters $PSBoundParameters
            Write-PWSHYBKPIVLog -Config $config -Level Information -CmdletName $MyInvocation.MyCommand.Name `
                -Message "Key imported into $slotDescription"
        } catch {
            Write-PWSHYBKPIVLog -Config $config -Level Error -CmdletName $MyInvocation.MyCommand.Name -Message "Key import failed: $_"
            throw
        }
    }
}