We're experiencing a couple of issues with our wifi configuration profiles and the renewal process.
1) In our environment of ~600 Macs, we've seen a few people each week that get dropped off of wifi. It appears that the configuration profile we have configured for network is attempting to re-try and fails. a) To remedy this, we normally remove from JAMF, then re-enroll and reboot and this reapplies the profile automatically. Alternatively, we created a clone of our wifi configuration profile and placed it in Self Service to allow people to try to reconnect. However, this did not work 100% of the time. Our helpdesk has a better success rate by downloading the mobileconfig and then installing it locally. Now I'm finding we can't manage these since it was not installed by JSS. What's the best way to clean this up?
2) We're replacing our CA server, which means we need to update all of our certificates. I'll need to upload the new root and sub certificates to all machines and reconnect to wifi. In our last renewal, we found that users that were on wifi were hit and miss for getting their configuration profile updated and were kicked off of wifi in the process. Is there a trick to getting this working 100% of the time?
Configuration profile setup:
Our configuration profile adds the root & intermediate certificate, then uses an AD certificate payload to request the user certificate from our Windows server. Then the "network" payload is configured to connect to the wifi using the AD certificate. (All machines have this installed automatically by JSS and JSS only)
We also have a clone of the profile above that is placed in Self Service. Some machines have had this profile installed locally on their machine outside of JSS by running the .mobileconfig.