Skip to main content
Question

CFNetwork SSLHandshake failed (-9807)

  • August 18, 2016
  • 6 replies
  • 32 views

Forum|alt.badge.img+5

Everything appears to be working find with the JSS and the clients but if we run sudo jamf policy or sudo jamf recon in Terminal, we see the error: CFNetwork SSLHandshake failed (-9807).

6 replies

Forum|alt.badge.img+15
  • Contributor
  • August 18, 2016

Sounds like a cert error. This on all machines? Just one?


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • August 20, 2016

@ksanborn Proxy between JSS & clients doing SSL inspection?


Forum|alt.badge.img+3
  • New Contributor
  • September 15, 2016

Hello @ksanborn

Were you able to resolve this issue? I'm asking because I'm currently experiencing the same problem. I've spent several hours trying to figure this out with no success. This first appeared after I upgraded the JSS and clients to version 9.96. Any help would be great. Thanks!


Forum|alt.badge.img+9
  • Contributor
  • September 15, 2016

I know I experienced this way back. I think the issue (for us) was that we needed to update our ciphers on the JSS side - but I'm still trying to remember (and check my email). Or that we had to remove some older (weaker) ciphers from the list.... I feel like it was something like that.


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • September 15, 2016

@seansb you mean this?


Forum|alt.badge.img+9
  • Contributor
  • September 15, 2016

@bentoms - I'm still struggling to recall but I'm fairly sure the issue was that we had those ciphers plus some old ones mixed in, I had to remove the old ones before the binary and Self-Service started working correctly.

Our issue was that we did the JSS upgrade - all of a sudden Self-Service policies weren't working. The logs on the local machine kept showing a handshake error (slightly different than OPs) every time a policy was called via SS.

I think the tl;dr of it was that we needed to upgrade our Java version because older versions of Java needed to use an old cipher which was upsetting Self-Service. Once we updated Java (and removed the old ciphers) I think everything was fine. Man it feels like forever ago.