Anyone else using CIS Benchmark scripts for Jamf written by @kenglish?
We're running the CIS scripts found here: https://github.com/jamfprofessionalservices/CIS-for-macOS-Sierra
After the scripts are run and the machine is rebooted, it hangs after FileVault login and won't log in.
After we reinstall Sierra (or High Sierra) on top of itself, it seems to resolve the issue.
At first I thought it was related to 10.12.6 but when we tried on 10.12.5, the same issues occurred.
We're also finding that it takes several passes to get from 0% compliancy down to 30+ failures and then down to 7-8 failures that never quite resolve.
Would love some discussion and insight here.
Thanks!
PS - Here are the failures...
CIS Audit Count: 7
CIS Audit List:
2.3.4 Set a screen corner to Start Screen Saver
2.5.1 Disable Wake for network access
2.5.2 Disable sleeping the computer when connected to power
5.4 Automatically lock the login keychain for inactivity
5.12 Create a custom message for the Login Screen
5.13 Create a Login window banner
6.2 Turn on filename extensions
According to https://github.com/jamfprofessionalservices/CIS-for-macOS-Sierra/blob/master/README.md, the following is expected...
5.13 Create a Login window banner
Everything else... Hmmm...