Private/ASD/Invoke-APIOnypheASDBootstrapCertsoWildcard.ps1
|
Function Invoke-APIOnypheASDBootstrapCertsoWildcard { <# .SYNOPSIS create input for Invoke-OnypheAPIV2 function and then call it to query the ASD Bootstrap Certso Wildcard APIv1 .DESCRIPTION create input for Invoke-OnypheAPIV2 function and then call it to query the ASD Bootstrap Certso Wildcard APIv1 - seeds a wildcard-domain search from a certificate subject.organization value, discovering wildcard domain pattern(s) (e.g. *.example.com) linked to it. BETA endpoint, requires a Griffin View or Griffin View ASM Edition subscription with a non-commercial use licence (see Get-OnypheUserInfo's asd.stdapis property). Uses the "certso"-keyed request body, same shape as Invoke-APIOnypheASDDomainCertso/Invoke-APIOnypheASDIpCertso, NOT the "domain"-keyed body its "wildcard" name might suggest - confirmed live: sending a "domain" key instead returns HTTP error 1002 "certso: parameter error: certso not given". Live-tested 2026-09-19: "ONYPHE" returned HTTP error 1006 "search failed: no result found"; "DigiCert Inc" returned a clean "success" with 0 results; "Bleu SAS" returned HTTP error 1011 "too many results, you should create a task" - same astask/Wait-OnypheASDTask background-task mode as Invoke-APIOnypheASDOrgInventory/Invoke-APIOnypheASDDomainExist. Confirmed end-to-end: resending with "astask":"true" and polling via Wait-OnypheASDTask eventually returned a clean "success" with 0 results too - i.e. the error 1011 size estimate that triggers task mode does not guarantee the final result set is actually large once computed, worth remembering for any other endpoint that hits this error. -AsTask/task-result-retrieval is intentionally not exposed by this wrapper, same reasoning as Invoke-APIOnypheASDOrgInventory. .PARAMETER Certso -Certso string[] one or more certificate subject.organization values to query .PARAMETER IncludePattern -IncludePattern string[] patterns to grep and keep matching results .PARAMETER ExcludePattern -ExcludePattern string[] patterns to grep and exclude from results .PARAMETER Untrusted -Untrusted switch disable Onyphe's backend false-positive filtering (server default is enabled/trusted) .PARAMETER AsLines -AsLines switch render results as one JSON object per line instead of with context (server default is with context) .PARAMETER APIKEY -APIKey string{APIKEY} Set APIKEY as global variable .PARAMETER FuncInput -FuncInput hashtable original bound parameters of the calling wrapper, threaded through to the result object's cli-func_input property .OUTPUTS TypeName: PSOnyphe .EXAMPLE C:\PS> Invoke-APIOnypheASDBootstrapCertsoWildcard -Certso "Example Organization" #> [cmdletbinding()] Param ( [parameter(Mandatory=$true)] [ValidateNotNullOrEmpty()] [string[]]$Certso, [parameter(Mandatory=$false)] [ValidateNotNullOrEmpty()] [string[]]$IncludePattern, [parameter(Mandatory=$false)] [ValidateNotNullOrEmpty()] [string[]]$ExcludePattern, [parameter(Mandatory=$false)] [switch]$Untrusted, [parameter(Mandatory=$false)] [switch]$AsLines, [parameter(Mandatory=$false)] [ValidateLength(40,40)] [string]$APIKey, [parameter(Mandatory=$false)] [ValidateNotNullOrEmpty()] [hashtable]$FuncInput ) Process { if ($APIKey) {Set-OnypheAPIKey -APIKey $APIKey | out-null} $Body = [ordered]@{ certso = $Certso } if ($IncludePattern) { $Body.includep = $IncludePattern } if ($ExcludePattern) { $Body.excludep = $ExcludePattern } if ($Untrusted) { $Body.trusted = $false } if ($AsLines) { $Body.aslines = $true } $params = @{ request = "v1/asd/bootstrap/certso/wildcard" APIInfo = "asd/bootstrap/certso/wildcard" APIInput = @($Certso) APIKeyrequired = $true APIVersion = "1" Data = $Body | ConvertTo-Json } if ($FuncInput) { $params.add("FuncInput", $FuncInput) } Write-Verbose -message "URL Info : $($params.request)" Write-Verbose -message "POST JSON Data : $($Body | ConvertTo-Json)" Invoke-OnypheAPIV2 @params } } |