f65124fd99
Request-InfisicalCertificate -InstallChain could hang indefinitely. Adding a root certificate to CurrentUser\Root makes Windows raise a modal trust confirmation dialog, and X509Store.Add blocks until it is answered. When that dialog was hidden or the session non-interactive (scheduled task, MECM task sequence) the cmdlet appeared to stop right after installing the intermediate, with no indication why. A warning is now emitted before the blocking call. -StoreLocation now defaults to the process elevation when the caller does not supply it: LocalMachine when elevated, CurrentUser otherwise. This is what most callers want, and it sidesteps the trust prompt entirely because writing LocalMachine\Root already required elevation. Applied to both Request-InfisicalCertificate and Install-InfisicalCertificate; the resolved value is reported on the verbose stream and an explicit -StoreLocation wins. Chain routing is unchanged and already correct: self-signed certificates go to the Root store and everything else to CertificateAuthority, within whichever location was resolved. When the resolved location is LocalMachine and -KeyStorageFlags was not supplied, the private key is written to the machine key store. Without this the key lands in the calling user's profile while the certificate sits in LocalMachine\My, which is the usual cause of an installed certificate that reports no usable private key to a service. Reuse detection now searches the store location the install will write to rather than always searching CurrentUser, so -AllowRenewal and the existing certificate short-circuit behave consistently with where certificates land. Elevation detection moved to InfisicalCmdletBase (evaluated through the engine, since the module targets netstandard2.0 and carries no System.Security.Principal.Windows reference) and is shared with Write-InfisicalScepMdmProfileToWmi, which loses its private copy. README gains the fuller worked example, a genericized output transcript, and a "Where certificates get installed" section; cmdlet help updated to match. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>