/munki-enrollment-client

Munki Enrollment Client provides a means to enroll Mac systems with a Munki server using certificate-based authentication over HTTPS.

Primary LanguagePythonOtherNOASSERTION

About

The Munki Enrollment Client (MEC) is a Mac app written in Objective-C with included scripts writtin in Python. Working with the Munki Enrollment Server (MES), it enrolls the computer with a Munki repository, creating a computer manifest, private key, and certificate for per-device authentication. It joins the computer's manifest to an appropriate group manifest (via the included_manifests key in the computer's manifest), and it performs various “first boot” setup. Communication between the MEC and the MES is encrypted in transit with HTTPS.

The MEC is delivered to a client system via an installer package. Its package may be installed to enroll a Mac ad-hoc (without erasing and re-imaging it), and it may be installed at the end of an imaging procedure (such as a DeployStudio workflow). The installer package distributes these items:

  • /Applications/Munki Enrollment Client.app, the app including its embedded scripts, and
  • /Library/LaunchAgents/edu.gsu.mec.plist, the launch agent responsible for loading the MEC in the the Login Window context.

Besides installing the MEC, its installer package executes a postinstall script that does the following:

  • It touches /private/var/db/.AppleSetupDone on the installation target's volume to prevent the Setup Assistant from appearing. This is primarily for the “just imaged” case where a system may have had an image restored and the MEC should perform first boot setup.
  • It moves /private/etc/kcpasswd on the installation target's volume to a different path to temporarily disable automatic login. Automatic login is restored after the MEC completes its tasks.
  • It sets the DisableFDEAutoLogin key to true in the com.apple.loginwindow preference for the system domain. This temporarily disables FileVault's ability to bypass the login window after a disk is unlocked at boot. FileVault's ability to bypass the login window is restored after the MEC completes its tasks. FDE automatic login (by setting the DisableFDEAutoLogin key to true in the com.apple.loginwindow domain on the installation target's volume).

Building

This repository holds a single Xcode project which builds an Apple installer package for the MEC. The build-script.sh file may be adjusted as necessary. It is called at the end of the Xcode build sequence and is responsible for creating the installer package. The installer package for the MEC is actually a distribution product archive with a component package for the MEC and the component packages from the Munki tools. The Munki tools are downloaded from munkibuilds.org. Change the MUNKI_VERSION variable to specify what version of Munki tools should be included in the MEC package.

You'll also need to make some changes specific to your environment. This can be done before or after building, as configuration is stored in the Site class of the configuration.py module. This holds a number of configuration parameters such as your organization name, the URL for the Munki Enrollment Server, etc.

  • To edit before building, edit configuration.py in the Xcode project.
  • It is also possible to edit this file after building by modifying Contents/Resources/configuration.py inside the app wrapper and re-packaging the product. This is not recommended, but illustrates that the configuration is not compiled.

Authors

  • The MEC and MES were created by Gerrit DeWitt (gdewitt@gsu.edu), but the overall idea for the project is not novel. For example, a project called “Munki Manifest Selector” (noted in Sources) captures the overall design goal.
  • MEC relies heavily on publicly disclosed methods and open source items. For license terms, authors, and references, refer to the Sources section.

Sources

Notes and How-To

  1. Conceptual Inspiration:
  2. Munki manifest format: https://github.com/munki/munki/wiki/Manifests
  3. Apple Serial Numbers: http://www.macrumors.com/2010/04/16/apple-tweaks-serial-number-format-with-new-macbook-pro/
  4. Local User & Group Manipulation:
  5. String Manipulation: http://www.tldp.org/LDP/abs/html/string-manipulation.html
  6. FileVault Automatic Login: https://support.apple.com/en-us/HT202842
  7. Package Creation: http://thegreyblog.blogspot.com/2014/06/os-x-creating-packages-from-command_2.html
  8. Manual Pages:
  9. Python:
  10. Objective-C Reference:
  11. Getting Notifications from Munki: NSDistributedNotificationCenter
  12. Misc: