Hello,
I've been changing our live JAMF system over from using a self-signed certificate to a proper public certificate. I finally got it all working Thursday afternoon. (Definition of "working": I was able to get a new Apple push certificate using it; communication between my JAMF server and Apple School Manager is working; I was able to reinstall a client and it picked up NDM and carried on happily.)
On Friday, I was off, which means that nobody was doing anything with the JAMF system or that client.
Today, I found that that client can't communicate with the JAMF server. And it lost the ability to communicate between 10:09 and 10:28 *Friday* morning. When I wasn't even there.
Log entries go from this:
Fri Jul 21 09:50:34 LISA-065 jamf[38385]: Checking for policies triggered by "recurring check-in"...
Fri Jul 21 09:50:38 LISA-065 jamf[38385]: Checking for patches...
Fri Jul 21 09:50:38 LISA-065 jamf[38385]: No patch policies were found.
Fri Jul 21 10:08:57 LISA-065 jamf[39031]: Checking for policies triggered by "recurring check-in"...
Fri Jul 21 10:09:01 LISA-065 jamf[39031]: Checking for patches...
Fri Jul 21 10:09:01 LISA-065 jamf[39031]: No patch policies were found.
...To this:
Fri Jul 21 10:28:52 LISA-065 jamf[39649]: Checking for policies triggered by "recurring check-in"...
Fri Jul 21 10:31:29 LISA-065 jamf[39649]: Could not connect to the JSS. Looking for cached policies...
Fri Jul 21 10:49:46 LISA-065 jamf[40390]: Checking for policies triggered by "recurring check-in"...
Fri Jul 21 10:49:47 LISA-065 jamf[40390]: Could not connect to the JSS. Looking for cached policies...
...With an occasional variant like this:
Mon Jul 24 12:52:09 LISA-065 jamf[106]:
There was an error.
Connection failure: "An SSL error has occurred and a secure connection to the server cannot be made."
But those are few and far between. In fact I don't think I get any of those unless I'm trying to get it to do things, i.e. it never did any of those over the weekend, it only started on them this morning. It may be that they only happen when I log onto the client.
Meanwhile, in the server logs, there is...not much happening; I can't find anything in the log that doesn't occur elsewhere in the log when there was nothing bad going on. Connection with Apple School Manager is still working (I have just been able to move another client onto this MDM, it appeared, I was able to check its box in a pre-stage enrollment, and later it became "Assigned").
So: anyone have any ideas why a client that was happy enough to go through MDM enrollment and installation, and receive all its configuration profiles and all of that stuff, should, just under 24 hours later, suddenly become unable to do so?
Thanks,
Lisa.