Skip to content

Android certs: non-critical issues #36052

Description

@getvictor

Android agent gets enroll secrets

Address undefined enroll secret selection and inconsistent error handling.

  • Error handling: The code fails hard if no enroll secrets exist, but this pattern is inconsistent across the codebase. In server/service/microsoft_mdm.go:1358, missing secrets are logged as a warning and execution continues. Decide whether this should halt processing or continue gracefully for the Android agent flow.

  • Line 144 (secret selection): GetEnrollSecrets (in server/datastore/mysql/app_configs.go:231) has no ORDER BY clause, so enrollSecrets[0] returns an arbitrary/undefined secret, not a deterministic "first" one.

Migration for our base Android profile

  • Our base profile should include the app so that it is installed right away when user enrolls the Android device. This means the app will be installed without any configs, and configs will be pushed down loater.
    • The migration means going through all enterprises via AMAPI and adding the Android app to them.
    • NO plan to do this right now

Resending certs

  • If a fleet variable is modified, like IDP USER, the certificate template using that variable needs to be resend to Android host.
    • Filed new subtask for this: #36681

node_key security

Dev experience

Consistency

  • If server goes down while policies are being sent to Google, then we will not resend them.
    • Included the fix in this issue: #36684

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

#g-supply-chainSupply Chain product group~sub-taskA technical sub-task that is part of a story. (Not QA'd. Not estimated.)

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions