Skip to main content
Question

jss now in dmz - best way to know what devices need to be re-enrolled

  • October 3, 2014
  • 6 replies
  • 23 views

ImAMacGuy
Forum|alt.badge.img+23

I've got our JSS in the DMZ now. Apparently I need to re-enroll the existing machines into the new DMZ jss link. Is there an easy way to show/group/list what machines need to be done vs what has been done? I was thinking of deploying a new QuickAdd, however, I want to give the ability to use the https://jss.server.com:port/enroll as well.

6 replies

Nick_Gooch
Forum|alt.badge.img+9
  • Contributor
  • October 3, 2014

I'm pretty sure you don't need to re-enroll, unless you had to change your host name? At least we didn't... Added the jss in the DMZ with the same host name as the internal jss. Set up dns to point to the proper jss. Copied the cert keystore to the dmz so it matched the internal, modified the server.xml, restarted tomcat and we were good to go.


Forum|alt.badge.img+15
  • Contributor
  • October 5, 2014

You may need to do is check what you are pointing to: prior to adding the pinholed site we were pointing to OurJSS. What you need to make sure you are pointing to is the fully qualified name: OurJSS.ourserver.com. That change was made in the JSS, and we also created a policy that changed OurJSS to OurJSS.ourserver.com


Forum|alt.badge.img+4
  • Contributor
  • October 5, 2014

if you end up having to re-enrol everything (sometimes its needed) you could run an inventory on all devices. then run a report showing only devices that havent checked back in since the change over date.
unsure of the specifics of the report but you should be able to see who hasnt checked in since a certain date


ImAMacGuy
Forum|alt.badge.img+23
  • Author
  • Esteemed Contributor
  • October 6, 2014

we are going to have to reenroll, we changed the DNS name since we were just using the server name before. So there's no EA or anything we can do to have it pull the current JSS connection?


Forum|alt.badge.img+16
  • Honored Contributor
  • October 6, 2014

If you keep your old internal DNS record intact along with the new one that works both internally and externally and then change the management url in the jss, when the clients check in at the old address internally they will update their management plist file with the new address and start checking in using the one that works both internally and externally.


Forum|alt.badge.img+16
  • Honored Contributor
  • October 6, 2014

I should say my experience doing this only applies to OS X machines.