Posted on 08-30-2017 09:39 AM
Hey everyone. Been enrolling our existing stock of Macs, current enrollment doesn't actually call any other policies or install anything else. MOST of the machines can be managed with Casper Remote successfully, but a few absolutely refuse to ever connect.
A few points:
- Our enrollment configuration is set to "Ensure SSH is enabled."
- There are no firewalls or anything between me and the machines being managed.
- Other policies and such execute fine on the machines.
Anything obvious I am missing here?
Posted on 08-30-2017 09:43 AM
Also, trying to SSH into one of these machines by IP in Terminal never connects.
Posted on 08-30-2017 11:03 AM
Verify via Network Utility that the SSH port is open, then verify in the JSS what your management account is for those affect Macs. In Casper Remote what if any messages do you get in order. You might try recreating a new QuickAdd.pkg to see if that helps, but based upon what you have said it looks like the SSH port is blocked, especially since your policies are executing.
Can you login as root and see if you can connect? Any commonality among those systems you are unable to SSH into?
Posted on 08-30-2017 11:44 AM
I've seen this issue after removing the jamf Framework and re-enrolling. Removing the framework does not remove the "casperadmin" Management Account user (which is what I name mine) and I've found that I need to remove casperadmin using Directory Utility before I re-enroll a Mac.
Another theory (which I haven't proved/disproved): I have a strong suspicion that users who have altered their .ssh config files have broken my ability to use Casper Remote on their Macs.