Every time we've tried enabling certificate based communication, we've seen issues where a subset of our machines stop talking to the JSS until we manually re-enrolling them, so we always end up having to turn it off shortly after turning it on.
About 2 months ago, I turned cert based off and sent out a jamf enroll policy per jamfs suggestion in the hope I could enable cert based communication without issue before we started our mass reimaging this summer.
We are ready to start imaging, so I re-enabled cert based communication, but unfortunately, I'm seeing issues with some freshly imaged machines that aren't talking to the JSS post image (so our post image scripts that run manual triggers don't run). So far it's happened on 2 out of 10 test reimages, and we have over 5000 machines to image in the next few weeks so manually enrolling or doing quick add isn't something we want to do.
On a machine with the issue -
checkJSSConnection completes fine
recon produces 401 error
enroll gets machine back into working state, but at this point the post image scripts haven't ran and machine needs to be reimaged anyway
Seems similar to this thread
http://jamfnation.jamfsoftware.com/discussion.html?id=3888
Anyone have any suggestions? I am talking with JAMF too but am under a time crunch now.
