PRECONFIGURED INSTALLER FOR UNMANAGED DEVICES
An installation service has been created to facilitate secure installation of software on unmanaged devices. An organization will set up, with the service, an application to be installed on devices of users of the organization, each with a configuration specified by the administrator. The service associates each pairing of installer and configuration with a random or pseudo-random identifier. When the service receives a request with an identifier, the service will retrieve the installer assigned the identifier, embed an identifier of the configuration into the installer without invalidating authenticity of the installer, and deliver it to the requestor. After the installer is validated and run on a device, the installer will detect the configuration identifier, authenticate the configuration identifier, and request the configuration data from the service. In response, the service provides the configuration data, digitally signed, to the installer.
1 . A method comprising:
assigning a randomly generated identifier to each of a set of one or more signed installers;
based on receipt of a first request that includes a first uniform resource locator (URL) for a service and a first identifier,
retrieving a first of the set of signed installers assigned a first of the randomly generated identifiers that matches the first identifier;
determining first configuration data for the first signed installer and an indicator of the first configuration data;
embedding a validation identifier corresponding to the first configuration data indicator into the first signed installer;
communicating to a requestor of the first request the first signed installer; and
based on receipt of a second request that indicates the first configuration data indicator,
retrieving the first configuration data; and
communicating to the requestor the first configuration data and corresponding authentication data for the first configuration data.
2 . The method of claim 1 , wherein retrieving the first signed installer comprises searching among the randomly generated identifiers for the first identifier.
3 . The method of claim 1 further comprising:
in response to an installer configuration request,
the service assigning, in a backend associated with the service, the first configuration data indicator to the first configuration data and associating the first configuration data with the first signed installer; and
communicating the first URL indicating the first signed installer and the first randomly generated identifier,
wherein assigning the one or more randomly generated identifiers is by the service.
4 . The method of claim 1 , wherein embedding the indicator of the first configuration data comprises embedding the indicator into an area of the first signed installer that does not invalidate the first signed installer or into a path attribute of the first signed installer.
5 . The method of claim 1 further comprising setting an expiration time for the first URL.
6 . The method of claim 1 , wherein the first request also includes an authentication token issued by an identity provider.
7 . The method of claim 6 further comprising:
the service, which is receiving the requests and responding to the requests,
creating a first session based on an authentication token in response to the second request, wherein the session is with a backend endpoint associated with the service; and
updating the first configuration data with information about the first session prior to communicating the first configuration data.
8 . The method of claim 1 further comprising digitally signing the indicator of the first configuration data and the first configuration data.
9 . The method of claim 1 , wherein the indicator of the first configuration data is one of a URL, a uniform resource identifier (URI), executable code for retrieving the configuration data, and an identifier determined by the service receiving the first and second requests and responding to the requests.
10 . The method of claim 1 further comprising the requestor validating the first signed installer, running the first signed installer after successful validation, and validating the indicator of the first configuration data, wherein the indicator was digitally signed prior to communication of the first signed installer and the second request is communicated after successful validation of the indicator of the configuration data.
11 . The method of claim 1 further comprising the requestor validating the first configuration data based on the authentication data.
12 . A non-transitory, machine-readable medium having stored thereon program code, the program code comprising instructions to:
assign a random identifier to each of a set of one or more signed installers;
based on receipt of a first request that includes a first uniform resource locator (URL) for a service and a first identifier,
retrieve a first of the set of signed installers assigned a first of the randomly generated identifiers that matches the first identifier;
determine first configuration data for the first signed installer and an indicator of the first configuration data;
embed a validation identifier corresponding to the first configuration data indicator into the first signed installer;
communicate to a requestor of the first request the first signed installer; and
based on receipt of a second request that indicates the first configuration data indicator,
retrieve the first configuration data; and
communicate to the requestor the first configuration data and corresponding authentication data for the first configuration data.
13 . The non-transitory, machine-readable medium of claim 12 , wherein the program code further comprises instructions to:
in response to an installer configuration request,
assign, in a backend associated with the service, the first configuration data indicator to the first configuration data and associate the first configuration data with the first signed installer; and
communicate the first URL indicating the first signed installer and the first randomly generated identifier.
14 . The non-transitory, machine-readable medium of claim 12 , wherein the instructions to embed the indicator of the first configuration data comprise instructions to embed the indicator into an area of the first signed installer that does not invalidate the first signed installer or into a path attribute of the first signed installer.
15 . The non-transitory, machine-readable medium of claim 14 , wherein the program code further comprises instructions to:
create a first session based on an authentication token in response to the second request, wherein the session is with a backend endpoint associated with the service, wherein the first request also includes the authentication token issued by an identity provider; and
update the first configuration data with information about the first session prior to communicating the first configuration data.
16 . The non-transitory, machine-readable medium of claim 12 , wherein the program code further comprises instructions to digitally sign the indicator of the first configuration data and the first configuration data.
17 . An apparatus comprising:
a processor; and
a machine-readable medium having instructions stored thereon executable by the processor to cause the apparatus to,
assign a randomly generated identifier to each of a set of one or more signed installers;
based on receipt of a first request that includes a first uniform resource locator (URL) for a service and a first identifier,
retrieve a first of the set of signed installers assigned a first of the randomly generated identifiers that matches the first identifier;
determine first configuration data for the first signed installer and an indicator of the first configuration data;
embed a validation identifier corresponding to the first configuration data indicator into the first signed installer;
communicate to a requestor of the first request the first signed installer; and
based on receipt of a second request that indicates the first configuration data indicator,
retrieve the first configuration data; and
communicate to the requestor the first configuration data and corresponding authentication data for the first configuration data.
18 . The apparatus of claim 17 , wherein the machine-readable medium further has stored thereon instructions executable by the processor to cause the apparatus to:
in response to an installer configuration request,
assign, in a backend associated with the service, the first configuration data indicator to the first configuration data and associate the first configuration data with the first signed installer; and
communicate the first URL indicating the first signed installer and the first randomly generated identifier.
19 . The apparatus of claim 17 , wherein the instructions to embed the indicator of the first configuration data comprise instructions executable by the processor to cause the apparatus to embed the indicator into an area of the first signed installer that does not invalidate the first signed installer or into a path attribute of the first signed installer.
20 . The apparatus of claim 19 , wherein the machine-readable medium further has stored thereon instructions executable by the processor to cause the apparatus to:
create a first session based on an authentication token in response to the second request, wherein the session is with a backend endpoint associated with the service, wherein the first request also includes the authentication token issued by an identity provider; and
update the first configuration data with information about the first session prior to communicating the first configuration data.
21 . The apparatus of claim 17 , wherein the machine-readable medium further has stored thereon instructions executable by the processor to cause the apparatus to digitally sign the indicator of the first configuration data and the first configuration data.