#!/bin/bash # ============================================================================== # Enterprise Linux Workstation Onboarding Script for Ubuntu LTS # Installs: CrowdStrike Falcon (via API), TeamViewer (Host/Full with Design & Deploy), # Microsoft Edge, Microsoft Intune Portal # Organization: IfchorGalbraiths Group (igship.net) # ============================================================================== set -euo pipefail # ------------------------------------------------------------------------------ # CONFIGURATION # ------------------------------------------------------------------------------ # CrowdStrike Customer ID with Checksum (CCID) FALCON_CID="C1A8220187C943F5BDACDBFAA67DCA3B-86" # CrowdStrike API Credentials (Scope: Sensor Download: Read) FALCON_API_BASE="https://api.crowdstrike.com" FALCON_CLIENT_ID="8e9d398aed7740099ed17bc100aa2434" FALCON_CLIENT_SECRET="1374u0jVmPrZhFB8QgA6bW2Cpox95OTqRKLeGNdn" # TeamViewer Design & Deploy Assignment Tokens # Assignment ID -> Group: Intune Devices / IfchorGalbraiths (Unattended Remote Support) TV_ASSIGNMENT_TOKEN="0001CoABChBr_3NAzM0R76KIJNKzWSyVEigIACAAAgAJABrNc8ZaF9CYJpVB8qgSzohRQ7YcvQICAUYxzvJWqXLBGkBt7fbebrEdJU5Gr_7Ghz2ogHsl5tX4qYjflhPdhAp9p8Uas5a-GaMl4tlm9UaIRIuCd0f9nJCfRzy0NzvkxfvxIAEQop65kw8=" TV_HOST_TOKEN="$TV_ASSIGNMENT_TOKEN" TV_FULL_TOKEN="$TV_ASSIGNMENT_TOKEN" TV_ASSIGNMENT_ID="" # ------------------------------------------------------------------------------ # 1. Parse Command Line Arguments TV_MODE="" for arg in "$@"; do case $arg in --teamviewer=host|--tv=host|host) TV_MODE="host" ;; --teamviewer=full|--tv=full|full) TV_MODE="full" ;; --skip-teamviewer|--no-teamviewer|none) TV_MODE="none" ;; --tv-id=*|--assignment-id=*) TV_ASSIGNMENT_ID="${arg#*=}" ;; esac done echo "======================================================" echo " Starting Enterprise Linux Workstation Configuration " echo " Organization: IfchorGalbraiths Group " echo "======================================================" # 2. Verify Root/Sudo if [ "$EUID" -ne 0 ]; then echo "[-] ERROR: Please run as root or using sudo: sudo bash $0" exit 1 fi # 3. Detect TeamViewer Selection if not passed via arguments if [ -z "$TV_MODE" ]; then TV_MODE="host" fi # Assign the appropriate token based on mode if not explicitly overridden if [ -z "$TV_ASSIGNMENT_ID" ]; then if [ "$TV_MODE" = "host" ]; then TV_ASSIGNMENT_ID="$TV_HOST_TOKEN" elif [ "$TV_MODE" = "full" ]; then TV_ASSIGNMENT_ID="$TV_FULL_TOKEN" fi fi # 4. Detect Ubuntu Release Codename UBUNTU_CODENAME=$(lsb_release -cs) UBUNTU_RELEASE=$(lsb_release -rs) echo "[+] Detected Ubuntu release: $UBUNTU_RELEASE ($UBUNTU_CODENAME)" echo "[+] TeamViewer Target: $TV_MODE" # 5. Install Core Dependencies echo "[+] Installing prerequisite utilities..." apt update -y apt install -y curl jq gpg apt-transport-https lsb-release gnome-keyring libsecret-1-0 libsecret-tools xdg-desktop-portal-gtk xdg-desktop-portal-gnome openssh-server unattended-upgrades systemctl enable --now ssh || true # Configure automated security updates echo "[+] Enabling automated background OS security updates (unattended-upgrades)..." cat << 'EOF' > /etc/apt/apt.conf.d/20auto-upgrades APT::Periodic::Update-Package-Lists "1"; APT::Periodic::Unattended-Upgrade "1"; APT::Periodic::Download-Upgradeable-Packages "1"; APT::Periodic::AutocleanInterval "7"; EOF systemctl enable --now unattended-upgrades || true # Pre-configure desktop portal to route secrets to gnome-keyring mkdir -p /etc/xdg/xdg-desktop-portal cat << 'EOF' > /etc/xdg/xdg-desktop-portal/portals.conf [preferred] default=gnome;gtk; org.freedesktop.impl.portal.Secret=gnome-keyring EOF # Automatically initialize default login keyring for the desktop user if absent PRIMARY_USER="${SUDO_USER:-$(logname 2>/dev/null || echo '')}" if [ -n "$PRIMARY_USER" ] && [ "$PRIMARY_USER" != "root" ]; then U_HOME=$(eval echo "~$PRIMARY_USER") K_DIR="$U_HOME/.local/share/keyrings" if [ ! -f "$K_DIR/login.keyring" ] && [ ! -f "$K_DIR/default" ]; then echo "[+] Pre-initializing default login keyring for $PRIMARY_USER..." mkdir -p "$K_DIR" echo -n "login" > "$K_DIR/default" cat << 'EOF' > "$K_DIR/login.keyring" [keyring] display-name=Login ctime=0 mtime=0 lock-on-idle=false lock-after=false EOF chmod 700 "$K_DIR" chmod 600 "$K_DIR/default" "$K_DIR/login.keyring" chown -R "$PRIMARY_USER:$PRIMARY_USER" "$K_DIR" fi # Clean any stale Intune cache files rm -rf "$U_HOME/.cache/intune-portal" "$U_HOME/.config/intune-portal" 2>/dev/null || true fi # ------------------------------------------------------------------------------ # 6. Fetch & Install Latest CrowdStrike Falcon via Official API # ------------------------------------------------------------------------------ echo "------------------------------------------------------" echo "[+] Authenticating with CrowdStrike Falcon API..." TOKEN_RESP=$(curl -s -X POST "${FALCON_API_BASE}/oauth2/token" \ -H "accept: application/json" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "client_id=${FALCON_CLIENT_ID}&client_secret=${FALCON_CLIENT_SECRET}") BEARER_TOKEN=$(echo "$TOKEN_RESP" | jq -r '.access_token // empty') if [ -z "$BEARER_TOKEN" ]; then echo "[-] Failed to obtain CrowdStrike API token. Response was:" echo "$TOKEN_RESP" exit 1 fi echo "[+] Querying CrowdStrike API for latest Ubuntu amd64 sensor..." INSTALLER_SHA256=$(curl -s -X GET "${FALCON_API_BASE}/sensors/combined/installers/v1?filter=os%3A%22Ubuntu%22" \ -H "Authorization: Bearer ${BEARER_TOKEN}" \ | jq -r '.resources[] | select(.name | endswith("amd64.deb")) | .sha256' | head -n 1) if [ -z "$INSTALLER_SHA256" ]; then echo "[-] Failed to locate latest Ubuntu amd64 sensor package from CrowdStrike API." exit 1 fi if ! dpkg -s falcon-sensor >/dev/null 2>&1; then echo "[+] Downloading sensor package (SHA256: ${INSTALLER_SHA256})..." curl -s -X GET "${FALCON_API_BASE}/sensors/entities/download-installer/v1?id=${INSTALLER_SHA256}" \ -H "Authorization: Bearer ${BEARER_TOKEN}" \ -o /tmp/falcon-sensor.deb echo "[+] Installing Falcon sensor package..." dpkg -i /tmp/falcon-sensor.deb || apt-get install -f -y rm -f /tmp/falcon-sensor.deb else echo "[i] Falcon sensor package is already installed on this machine." fi echo "[+] Registering CrowdStrike CID..." /opt/CrowdStrike/falconctl -s -f --cid="$FALCON_CID" || true echo "[+] Starting Falcon service..." systemctl enable falcon-sensor || true systemctl restart falcon-sensor || true if systemctl is-active --quiet falcon-sensor; then echo "[✓] CrowdStrike Falcon Sensor is active and reporting." else echo "[!] Notice: Falcon service did not start cleanly. Inspecting reason:" journalctl -u falcon-sensor.service -n 5 --no-pager || true if command -v mokutil >/dev/null 2>&1; then echo " Secure Boot state: $(mokutil --sb-state 2>/dev/null || echo 'Unknown')" fi fi # ------------------------------------------------------------------------------ # 7. Install TeamViewer & Perform Design & Deploy Assignment # ------------------------------------------------------------------------------ echo "------------------------------------------------------" if [ "$TV_MODE" = "host" ]; then echo "[+] Downloading & Installing TeamViewer Host (Remote Support)..." curl -fSsL -o /tmp/teamviewer-host.deb "https://download.teamviewer.com/download/linux/teamviewer-host_amd64.deb" apt-get install -y /tmp/teamviewer-host.deb || apt-get install -f -y rm -f /tmp/teamviewer-host.deb systemctl enable teamviewerd || true systemctl start teamviewerd || true echo "[✓] TeamViewer Host successfully installed." elif [ "$TV_MODE" = "full" ]; then echo "[+] Downloading & Installing TeamViewer Full Client (Admin Edition)..." curl -fSsL -o /tmp/teamviewer.deb "https://download.teamviewer.com/download/linux/teamviewer_amd64.deb" apt-get install -y /tmp/teamviewer.deb || apt-get install -f -y rm -f /tmp/teamviewer.deb systemctl enable teamviewerd || true systemctl start teamviewerd || true echo "[✓] TeamViewer Full Client successfully installed." else echo "[*] TeamViewer installation skipped as requested." fi # Execute Design & Deploy Assignment if [ "$TV_MODE" != "none" ] && [ -n "$TV_ASSIGNMENT_ID" ]; then echo "[+] Configuring TeamViewer EULA and starting daemon..." # Ubuntu 24.04 AppArmor compatibility fix sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 >/dev/null 2>&1 || true echo "kernel.apparmor_restrict_unprivileged_userns = 0" > /etc/sysctl.d/99-teamviewer.conf 2>/dev/null || true # Disable Wayland in GDM so TeamViewer remote control captures desktop without black screen if [ -f /etc/gdm3/custom.conf ]; then echo "[+] Disabling Wayland in GDM for TeamViewer remote control display support..." sed -i 's/^#WaylandEnable=false/WaylandEnable=false/' /etc/gdm3/custom.conf if ! grep -q "^WaylandEnable=false" /etc/gdm3/custom.conf; then sed -i '/\[daemon\]/a WaylandEnable=false' /etc/gdm3/custom.conf fi fi mkdir -p /opt/teamviewer/config /etc/teamviewer if [ ! -f /opt/teamviewer/config/global.conf ] || ! grep -q "EulaAccepted" /opt/teamviewer/config/global.conf; then echo "[int32] EulaAccepted = 1" >> /opt/teamviewer/config/global.conf echo "[int32] EulaAcceptedRevision = 6" >> /opt/teamviewer/config/global.conf fi chmod 644 /opt/teamviewer/config/global.conf 2>/dev/null || true systemctl restart teamviewerd || true sleep 5 echo "[+] Waiting for TeamViewer to connect to the cloud and obtain an ID..." # Polling: Wait up to 45s for the daemon to acquire a valid TeamViewer ID TRIES=0 MAX_TRIES=15 while [ $TRIES -lt $MAX_TRIES ]; do TV_ID=$(teamviewer info 2>/dev/null | grep -E "TeamViewer ID:[[:space:]]+[0-9]+" | awk '{print $NF}' || true) if [ -n "$TV_ID" ]; then echo "[✓] TeamViewer daemon online! Acquired ID: $TV_ID" break fi TRIES=$((TRIES + 1)) echo " Waiting for daemon to negotiate cloud connection ($TRIES/$MAX_TRIES)..." sleep 3 done echo "[+] Assigning workstation to TeamViewer Management Console for Easy Access..." if teamviewer assignment --id "$TV_ASSIGNMENT_ID" --reassign 2>/dev/null || teamviewer assignment --id "$TV_ASSIGNMENT_ID" 2>/dev/null; then echo "[✓] TeamViewer successfully assigned to corporate account with Easy Access!" else echo "[!] Warning: TeamViewer assignment command returned non-zero. Verifying status..." teamviewer info || true fi fi # ------------------------------------------------------------------------------ # 8. Configure Microsoft Repositories & Install Edge / Intune # ------------------------------------------------------------------------------ echo "------------------------------------------------------" echo "[+] Configuring Microsoft package repository..." mkdir -p /usr/share/keyrings curl -fSsL https://packages.microsoft.com/keys/microsoft.asc | gpg --dearmor --yes -o /usr/share/keyrings/microsoft.gpg # Add Microsoft Edge repository echo "deb [arch=amd64 signed-by=/usr/share/keyrings/microsoft.gpg] https://packages.microsoft.com/repos/edge stable main" > /etc/apt/sources.list.d/microsoft-edge.list # Add Microsoft Intune repository echo "deb [arch=amd64 signed-by=/usr/share/keyrings/microsoft.gpg] https://packages.microsoft.com/ubuntu/$UBUNTU_RELEASE/prod $UBUNTU_CODENAME main" > /etc/apt/sources.list.d/microsoft-intune.list echo "[+] Installing Microsoft Edge and Intune Portal..." apt update -y apt install -y microsoft-edge-stable intune-portal echo "[+] Setting Microsoft Edge as the default corporate web browser..." update-alternatives --set x-www-browser /usr/bin/microsoft-edge-stable 2>/dev/null || true update-alternatives --set gnome-www-browser /usr/bin/microsoft-edge-stable 2>/dev/null || true mkdir -p /etc/xdg cat << 'EOF' >> /etc/xdg/mimeapps.list [Default Applications] text/html=microsoft-edge.desktop x-scheme-handler/http=microsoft-edge.desktop x-scheme-handler/https=microsoft-edge.desktop x-scheme-handler/about=microsoft-edge.desktop x-scheme-handler/unknown=microsoft-edge.desktop EOF if [ -n "$PRIMARY_USER" ] && [ "$PRIMARY_USER" != "root" ]; then su - "$PRIMARY_USER" -c "xdg-settings set default-web-browser microsoft-edge.desktop 2>/dev/null || true" su - "$PRIMARY_USER" -c "xdg-mime default microsoft-edge.desktop x-scheme-handler/http 2>/dev/null || true" su - "$PRIMARY_USER" -c "xdg-mime default microsoft-edge.desktop x-scheme-handler/https 2>/dev/null || true" su - "$PRIMARY_USER" -c "xdg-mime default microsoft-edge.desktop text/html 2>/dev/null || true" fi systemctl --system daemon-reload || true echo "======================================================" echo " [✓] Enterprise Configuration Complete! " echo "======================================================" echo " Next Steps:" echo " 1. A system reboot is recommended to activate all desktop keyring portals." echo " 2. After reboot, launch 'Microsoft Intune' from the applications menu." echo " 3. Sign in with your corporate email (e.g. jawh@igship.net) to complete enrollment." echo "======================================================" if [ -t 0 ]; then read -r -p "Reboot now to finalize desktop onboarding? [Y/n]: " do_reboot if [[ "${do_reboot:-y}" =~ ^[Yy]$ ]]; then echo "[+] Rebooting system in 3 seconds..." sleep 3 reboot fi fi