Skip to main content
Answer

Certificates delivered through configuration profiles disappearing (10.11)

  • December 4, 2015
  • 7 replies
  • 45 views

Forum|alt.badge.img+11

We use configuration profiles to deliver root certificates to our population (system keychain). On 10.11, possibly only 10.11.1, the configuration profile installs correctly, the certificates populate in the keychain, then some minutes later the certificates are gone despite the configuration profile still being there. This workflow has been fine on 10.10, anyone else seeing this?

Best answer by bentoms

Maybe OS X 10.11.2 resolves, as per: https://support.apple.com/en-us/HT205579

Resolves an issue where reinstalling a configuration profile containing a certificate payload causes the certificates to be removed instead of updated

7 replies

Forum|alt.badge.img+9
  • Contributor
  • December 4, 2015

I saw this same behavior after upgrading to 10.11 on some of our systems. Basically, I noticed after the upgrade, the wireless wouldn't work anymore and I kept getting a weird error that I needed to move closer to the AP. After doing a little research on my system I noticed that although the config profile was still there, the certs were not. Since that was the case, I couldn't simply re-run the policy to insert the certs because it conflicted with the profile that was already in place. I ended up re-writing the script to first check for the config profile and if found, remove it before trying to re-install the certs. So far this has worked without issue on all affected systems. I also haven't had a problem with them disappearing afterward.


Forum|alt.badge.img+16
  • Honored Contributor
  • December 7, 2015

I have seen this on my test systems too... The reason for me was that the config profile which contained the certificates was installed twice (once at imaging and afterwards via policy). We cannot use APNs to deliver the profile, so manually installing is the only way for us.

Modifying the policy and installing the profile only once was the solution for me.


Forum|alt.badge.img+18
  • Valued Contributor
  • December 7, 2015

I have also seen this behavior. Perhaps a bug in El Cap? What version of the JSS is everyone running? We are on 9.81, FWIW.


Forum|alt.badge.img+14
  • Contributor
  • December 8, 2015

Happened to me again today.

OS X 10.11.1 and JSS 9.81


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • Answer
  • December 9, 2015

Maybe OS X 10.11.2 resolves, as per: https://support.apple.com/en-us/HT205579

Resolves an issue where reinstalling a configuration profile containing a certificate payload causes the certificates to be removed instead of updated

Forum|alt.badge.img+11
  • Author
  • Valued Contributor
  • December 9, 2015

Looks like 10.11.2 does indeed fix the issue, thats a relief


Forum|alt.badge.img+5
  • Contributor
  • December 6, 2017

Its a product defect.

https://www.jamf.com/jamf-nation/discussions/24257/configuration-profiles-being-removed-and-reinstalled