Skip to main content
Question

Unable to find a JAMF Device Identity in the JAMF keychain

  • February 1, 2012
  • 17 replies
  • 76 views

bentoms
Forum|alt.badge.img+35

I'm getting the following error on some computers:

Error signing communication - Unable to find a JAMF Device Identity in the JAMF Keychain.

SSL is enabled & root cert is trusted on client, client is on 10.7..

any ideas?

17 replies

Forum|alt.badge.img+20
  • Valued Contributor
  • February 3, 2012

I am getting the same error all of the sudden on 10.7.3.


Forum|alt.badge.img+13
  • Contributor
  • February 17, 2012

Any updates on this? I'm getting these errors too while forcing a recon.


bentoms
Forum|alt.badge.img+35
  • Author
  • Hall of Fame
  • February 17, 2012

I ran a mass:

sudo jamf enroll

Through ARD, & seems ok for now.

Do you use a cert on the jss that's internally signed?


Forum|alt.badge.img+21
  • Contributor
  • August 9, 2012

Let me dust this one off. I'm now seeing this in my test environment, and I'm thinking it was after I installed our own certificates to the JSS. Doing the sudo jamf enroll certainly worked, but what's going on? Was hoping since this was back in February more information might be known.

10.8 Client
Windows 2008 R2 JSS version 8.6


Forum|alt.badge.img+19
  • Valued Contributor
  • August 10, 2012

Also seeing certificate issues in testing though still with Lion clients and 8.6 JSS. Have a ticket open with support.

Image computer ok
After the confirmation profiles are applied to add certificates the computer can no longer mount the distribution point - but can connect to JSS.
sudo jamf enroll after the certificates are installed and the client is ok once again.

Will update as I figure out more.


Forum|alt.badge.img+21
  • Contributor
  • August 10, 2012

Must be a certificates issue. I reverted back to the server.xml that installed with the JSS (not enforcing valid certs, just the JSS's) and I don't have the issues talking to the JSS after imaging anymore. Now whether the issue is how I implemented my certificates is the issue or the JSS is an issue might be waiting until Monday.


Forum|alt.badge.img+7
  • Contributor
  • August 14, 2012

I was running into a similar issue with Casper Suite 8.52 where even after re-imaging it would not accept the JAMF.keychain. What I did to resolve the issue was actually replacing the corrupt or incorrect keychain with a known good keychain. This makes me want to believe that it is a server side issue. Possibly to do with the way it distributes the JAMF.keychain file?


Forum|alt.badge.img+21
  • Contributor
  • August 14, 2012

This one is turning out to be sporadic...hooray! Imaging doesn't create the JAMF.keychain every now and then. I'm going to burn out a hard drive testing this week.


Forum|alt.badge.img+10
  • Contributor
  • August 14, 2012

Where should the JAMF.keychain be located?


Forum|alt.badge.img+21
  • Contributor
  • August 14, 2012

/Library/Application Support/JAMF/


Forum|alt.badge.img+10
  • Contributor
  • August 15, 2012

Hi all,

This is the first time I've seen this pop up in my Terminal.

So I trashed the file from /Library/Application Support/JAMF/JAMF.keychain

Rebooted, ran Recon (now, without the need to sudo) from the Terminal and no more error "Unable to find a JAMF Device Identity in the JAMF keychain"

What are the implications without having this file?

Thanks in advance!!


Forum|alt.badge.img+4
  • Contributor
  • August 21, 2012

Check if the time and other connectivity settings are correct as well.
I was getting this error because the time was wrong.


Forum|alt.badge.img+7
  • Contributor
  • February 14, 2013

Thanks, Paolo.

After spending a bit of time on the computer and searching on the Internet and trying all the posts above, your post was the last on this forum and was the only one that worked for me.


Forum|alt.badge.img+12
  • Contributor
  • March 8, 2013

*bump*

I'm seeing this sporadically as well. 10.8.2 images, JSS 8.62. Computers seem to image fine, then the first job sent with Casper remote turns up successful. Subsequent jobs fail with the above error.

Is there any other information available on this? I'll be opening a ticket with Jamf unless it's a simple fix. We are using the self-signed JSS-created cert for the server.


Forum|alt.badge.img+13
  • Valued Contributor
  • March 8, 2013

Check the time. Seriously. It's almost always that for me.


Forum|alt.badge.img+12
  • Contributor
  • April 19, 2013

Not the system time this time, or any time this has happened for that matter. Seems to be related to a trusted certificate from the JSS being not trusted.

issuing a jamf enroll recreates the trusted cert, and does some sort of edit to the jamf.keychain file.

Any ideas on what that might be, or be caused by?


Forum|alt.badge.img+1
  • New Contributor
  • August 23, 2019

6 Years later and I got this error as well. Here follows my 2cents on it :)

I Checked the network settings. I received the error because I had my proxy set to Auto Discover on the device(which was how we needed it for the some of our Uni URLs to work.

For the enrollment to complete without the above error I had to set the proxy servers. for Http and HTTPS. I have a policy that sets the proxy settings back to Auto Discover after enrollment