Hello,
We have a particular portion of our states website that is hosted / managed by them, I DON'T know the particulars of the backend, but can supply this info:
1.) The portion of the website that doesn't work (when managed) results in these errors in the console:
a.) com.apple.SecurityServer[93]: Sandbox denied authorizing right 'system.keychain.modify' by client '/System/Library/StagedFrameworks/Safari/WebKit.framework/Versions/A/XPCServices/com.apple.WebKit.Networking.xpc' [900]
b.) com.apple.SecurityServer[93]: Problem opening rules file "/etc/authorization": No such file or directory
c.) kernel[0]: Sandbox: com.apple.WebKit(900) deny(1) authorization-right-obtain system.keychain.modify
d.) com.apple.WebKit.Networking[900]: CFNetwork SSLHandshake failed (-128)
Disabling SIP has no effect, but removing the jss MDM results in full functionality.
When managed the browser(s) ask for system keychain access, but every credential is declined!
Any ideas of settings in the jss that might change this behavior?
If you need more info, please ask.