#!/bin/bash #timeout=1000000 # Installs TechIDAgent.macOS for a shared admin user account. # # sudo ./InstallSharedUser.sh [other agent options...] # # The heavy lifting is done by install-techidagent-6.874.mac.sh, which ships inside the # release tarball. This script only downloads it, checks it, and sets the agent options # afterwards -- the same split as the Windows InstallSharedUser.ps1. set -e set -o pipefail ClientGuid="$1" shift || true AdminUserName="$1" shift || true # everything left over is passed through to the agent, same as $OtherArgs on Windows OtherArgs=("$@") # check the ClientGuid to make sure it is set. It is the only one that must be set. if [ -z "$ClientGuid" ]; then echo 'ClientGuid needs to be set as the first parameter' >&2 exit 1 fi if [ -z "$AdminUserName" ]; then echo 'AdminUserName needs to be set as the second parameter' >&2 exit 1 fi # installer, launchctl and the pkg payload all need root. if [ "$(id -u)" -ne 0 ]; then echo 'This script must be run as root -- use sudo.' >&2 exit 1 fi version="techidagent.mac-6.874" PathRS="/usr/local/RuffianSoftware" SourceFile="https://ch001.ruffiansoftware.com/release/files/techidagent.mac-6.874.tgz" case "$SourceFile" in "{{"*) SourceFile="https://ch001.ruffiansoftware.com/release/files/techidagent.mac-6.874.tgz" ;; esac DestFile="$PathRS/$version.tgz" mkdir -p "$PathRS" if [ -f "$DestFile" ]; then rm -f "$DestFile" fi # --tlsv1.2 for the same reason the windows scripts pin the .NET security protocol: some older # machines still default to something the release host will not accept. curl --fail --location --silent --show-error --tlsv1.2 --output "$DestFile" "$SourceFile" # do a simple hash check to make sure we got a file that we are expecting. # This is only one of many ways we at Ruffian Software fight supply chain attacks. Everyone needs to do their part. # Both sides are lowercased -- shasum prints lowercase, Get-FileHash on the build machine prints uppercase. hash="$(shasum -a 256 "$DestFile" | awk '{print $1}' | tr '[:upper:]' '[:lower:]')" expected_hash="$(printf '%s' "045a7938e2555ed69752d10a41f568a2c7ce93bc306f70d925dc378630780547" | tr '[:upper:]' '[:lower:]')" if [ "$hash" != "$expected_hash" ]; then echo 'Hash of downloaded file does not match expected value.' >&2 exit 1 fi # make sure the path we are about to expand into is clean. if [ -d "$PathRS/$version" ]; then rm -rf "$PathRS/$version" fi mkdir -p "$PathRS/$version" tar -xzf "$DestFile" -C "$PathRS/$version" # install-techidagent-6.874.mac.sh calls "installer -pkg techidagent.mac-6.874.pkg" # with a relative path, so it has to be run from the directory it was unpacked into. It stops any # running daemon, installs the package and loads the daemon again. cd "$PathRS/$version" chmod a+x ./install-techidagent.mac.sh ./install-techidagent.mac.sh # The agent moved into an app bundle so that Login Items shows "TechIDAgent" rather than the # signing certificate name. Fall back to the old location so this still works if the machine ends # up running an older build than this script expects. AGENT="/Library/Application Support/TechIDAgent/TechIDAgent.app/Contents/MacOS/techidagent.mac" if [ ! -x "$AGENT" ]; then AGENT="/usr/local/bin/techidagent.mac" fi if [ ! -x "$AGENT" ]; then echo "The agent is not where it was expected after installing -- $AGENT is missing." >&2 exit 1 fi # set the options for this version. # have to set the clientguid first "$AGENT" installshared "$AGENT" shareduser "$AdminUserName" clientid "$ClientGuid" if [ ${#OtherArgs[@]} -gt 0 ]; then "$AGENT" shareduser "$AdminUserName" "${OtherArgs[@]}" fi # you can add other option setting here..... # unlike powershell there is no argument escaping to worry about, just quote anything with spaces # "$AGENT" otheroption "$ClientGuid" echo "TechIDAgent.macOS 6.874 installed for shared user $AdminUserName."