#!/bin/bash #timeout=1000000 # Updates an existing TechIDAgent.macOS install to 6.874. # # sudo ./UpdateAgent.sh # # Takes no arguments -- the agent options are already set on the machine and are left alone. # Refuses to run if the agent was never installed here, the same as the Windows UpdateAgent.ps1. set -e set -o pipefail # The macOS agent keeps its settings in a json file rather than the registry, so this is the # equivalent of the HKLM:\SOFTWARE\RuffianSoftware\TechIdentityManager check on windows. The # launchd plist is checked too, so a machine that has the daemon but has not written any settings # yet still updates. SettingsFile="/Library/Application Support/TechIDManager/settings.json" PlistFile="/Library/LaunchDaemons/com.ruffiansoftware.techidagent.plist" if [ -f "$SettingsFile" ] || [ -f "$PlistFile" ]; then echo "Data found indicating installation of TechIDAgent" else echo "No Data found indicating installation of TechIDAgent - NOT UPDATING" >&2 exit 1 fi # installer and launchctl need root. if [ "$(id -u)" -ne 0 ]; then echo 'This script must be run as root -- use sudo.' >&2 exit 1 fi version="techidagent.mac-6.874" PathRS="/usr/local/RuffianSoftware" SourceFile="https://ch001.ruffiansoftware.com/release/files/techidagent.mac-6.874.tgz" case "$SourceFile" in "{{"*) SourceFile="https://ch001.ruffiansoftware.com/release/files/techidagent.mac-6.874.tgz" ;; esac DestFile="$PathRS/$version.tgz" mkdir -p "$PathRS" if [ -f "$DestFile" ]; then rm -f "$DestFile" fi # --tlsv1.2 for the same reason the windows scripts pin the .NET security protocol: some older # machines still default to something the release host will not accept. curl --fail --location --silent --show-error --tlsv1.2 --output "$DestFile" "$SourceFile" # do a simple hash check to make sure we got a file that we are expecting. # This is only one of many ways we at Ruffian Software fight supply chain attacks. Everyone needs to do their part. # Both sides are lowercased -- shasum prints lowercase, Get-FileHash on the build machine prints uppercase. hash="$(shasum -a 256 "$DestFile" | awk '{print $1}' | tr '[:upper:]' '[:lower:]')" expected_hash="$(printf '%s' "045a7938e2555ed69752d10a41f568a2c7ce93bc306f70d925dc378630780547" | tr '[:upper:]' '[:lower:]')" if [ "$hash" != "$expected_hash" ]; then echo 'Hash of downloaded file does not match expected value.' >&2 exit 1 fi # make sure the path we are about to expand into is clean. if [ -d "$PathRS/$version" ]; then rm -rf "$PathRS/$version" fi mkdir -p "$PathRS/$version" tar -xzf "$DestFile" -C "$PathRS/$version" # update-techidagent.sh is the copy of the install script that ships in the tarball for exactly # this purpose. It stops the running daemon, installs the new package over the old one and loads # the daemon again, so there is nothing here that corresponds to "TechIDAgent.exe update" on # windows -- the existing settings are untouched and the daemon comes back up with them. cd "$PathRS/$version" chmod a+x ./update-techidagent.sh ./update-techidagent.sh echo "TechIDAgent.macOS updated to 6.874."