EncryptCredential
0.4.0
Execute commands like
"Hello World" | Convert-PlaintextToSecure
to get a string like
76492d1116743f0423413b16050a5345MgB8AEEAYQBmAEEAOABPAEEAYQBmAEYAKwBuAGQAegBxACsASQBRAGIAaQA0AEEAPQA9AHwANAAxAGEAYQBhADAAYwA3ADQAYwBiADkAYwAzADEAZgBkAGUAZQBkADQAOABhADIAMgA5AGUAMAAyADkANwBiADcAMQAyADgAOAAzADkAMwBiADA
Execute commands like
"Hello World" | Convert-PlaintextToSecure
to get a string like
76492d1116743f0423413b16050a5345MgB8AEEAYQBmAEEAOABPAEEAYQBmAEYAKwBuAGQAegBxACsASQBRAGIAaQA0AEEAPQA9AHwANAAxAGEAYQBhADAAYwA3ADQAYwBiADkAYwAzADEAZgBkAGUAZQBkADQAOABhADIAMgA5AGUAMAAyADkANwBiADcAMQAyADgAOAAzADkAMwBiADAANAA0ADcAMwA3ADQANgAxADMAYwBmADQAZQAyADIAMwBkAGQAMQBhADUAMAA=
This string can be decrypted by calling
"76492d1116743f0423413b16050a5345MgB8AEEAYQBmAEEAOABPAEEAYQBmAEYAKwBuAGQAegBxACsASQBRAGIAaQA0AEEAPQA9AHwANAAxAGEAYQBhADAAYwA3ADQAYwBiADkAYwAzADEAZgBkAGUAZQBkADQAOABhADIAMgA5AGUAMAAyADkANwBiADcAMQAyADgAOAAzADkAMwBiADAANAA0ADcAMwA3ADQANgAxADMAYwBmADQAZQAyADIAMwBkAGQAMQBhADUAMAA=" | Convert-SecureToPlaintext
and get back
Hello World
You better save the strings into variables ;-)
This module is used to double encrypt sensitive data like credentials, tokens etc.
Encryption happens in two layers: AES-256 with a random keyfile plus a machine-bound layer
(DPAPI on Windows, machine-id derived keys on Linux/macOS). So even if an attacker steals the
encrypted string AND the keyfile, it cannot be decrypted on another machine. With
-Scope User the string is additionally bound to the current user account.
At the first encryption a new random keyfile will be generated automatically.
The key is saved per default in your users profile, but can be exported into any other folder
via Export-Keyfile and loaded from there via Import-Keyfile.
Strings encrypted with older versions of this module stay decryptable (legacy format is
detected automatically).
Minimum PowerShell version
5.1
Installation Options
Owners
Copyright
(c) 2026 Apteco GmbH. All rights reserved.
Package Details
Author(s)
- florian.von.bracht@apteco.de
Tags
powershell Windows Linux Apteco
Functions
Convert-PlaintextToSecure Convert-SecureToPlaintext Export-Keyfile Import-Keyfile New-Keyfile
PSEditions
Dependencies
This module has no dependencies.
Release Notes
0.4.0 Encrypted strings are now really bound to the machine they were created on:
a second encryption layer via DPAPI (Windows) or machine-id derived keys with
AES + HMAC integrity protection (Linux/macOS) wraps the existing keyfile encryption.
So a stolen ciphertext plus keyfile is useless on another machine.
New -Scope parameter on Convert-PlaintextToSecure:
'Machine' (default), 'User' (additionally bound to the current account) and
'Portable' (old single-layer behaviour for moving ciphertexts between machines).
Decryption stays downwards compatible - strings from older versions are detected
and decrypted with the keyfile only.
Export-Keyfile now re-applies restrictive file permissions to the exported copy
and no longer switches to the new path if the copy failed.
Import-Keyfile now validates that the file is a usable 16/24/32 byte AES key.
Added a Pester test suite.
0.3.3 Fixed Convert-PlaintextToSecure calling New-Keyfile (the public, confirmation-gated wrapper with no -Path/-ByteLength params)
instead of the private New-KeyfileRaw when auto-creating a missing keyfile. This threw a parameter binding error
on any machine without an existing keyfile yet, e.g. fresh CI runners.
0.3.2 Fixed a bug where the module would not properly handle cases where the keyfile did not exist. Using New-Keyfile now instead of Create-Keyfile
0.3.1 Fixed returning an exception, when decryption failed instead of writing
an error and returning an empty string
0.3.0 Reworked the module with Claude AI to be more secure and robust, now using another way to create
a keyfile for salting. The old encryption method is still supported, so all
previously encrypted strings will stay valid UNTIL you call New-Keyfile. After that,
please re-encrypt all your credentials.
Added ACL and linux file permission handling for the keyfile.
Dispose the used AES object after encryption/decryption for better security.
Changed internal functions verbs for more consistency
Updated the copyright year to 2026
0.2.0 Tested successfully Linux support
0.1.2 Updated copyright to 2025
0.1.1 Bumped the copyright year to 2024
0.1.0 Making this module more mature with only explicit functions to export
Removing not needed verbose output, use -verbose to see it again
Fixed the path joining
0.0.2 Fixed a bug regarding output if a keyfile does not exist
0.0.1 Initial release through PSGallery
FileList
- EncryptCredential.nuspec
- EncryptCredential.psd1
- EncryptCredential.psm1
- Private\ConvertTo-CryptedOrbitPassword.ps1
- Private\Get-MachineIdentifier.ps1
- Private\New-KeyfileRaw.ps1
- Private\Protect-MachineBoundString.ps1
- Private\Read-Keyfile.ps1
- Private\Set-KeyfilePermission.ps1
- Private\Unprotect-MachineBoundString.ps1
- Public\Convert-PlaintextToSecure.ps1
- Public\Convert-SecureToPlaintext.ps1
- Public\Export-Keyfile.ps1
- Public\Import-Keyfile.ps1
- Public\New-Keyfile.ps1