Posted on 12-17-2013 10:21 AM
After upgrading from JSS 8.xx to 9.21 some of my systems now report MDM capability no. This systems are scattered all over and I would like to resolve this in a way that I don't need to go to the machine, and that does not disrupt the user.
If I wanted to use Casper Remote to accomplish this, let's say I wanted to use the command jamf enroll -prompt
I cannot do this because I cannot respond to the prompts.
Should I just use SSH to do this? I tried creating a quickadd.pkg but it won't work, many things won't work because I get the error 'A valid device signature is required to perform the action'.
I'm trying to figure out the best solution for dealing with this. I see on the forum others are having similar issues. What would be a good way to resolve this?
Thanks,
Aaron.
Posted on 12-17-2013 10:28 AM
I may have answered my own question. It seems to be working ok through SSH. I would still be interested in knowing if anyone else has a better solution. Also curious why this is happening and why it seems to be random.
Posted on 12-17-2013 10:47 AM
This was happening to me constantly a few months ago. After working with JAMF support we cleared out all outstanding APN commands and then resent them. This seemed to resolve the issue for awhile at least. It just started coming back recently. We are using 8.73 though. I have tons of profiles pushing to various machines and seems sometimes these get caught up is my new theory.
Gabe Shackney
Princeton Public Schools
Posted on 12-17-2013 10:48 AM
I tried this on one of the systems, rather than my test system and although everything looked right (used -verbose) it still says MDM Capability NO.
Posted on 12-17-2013 10:49 AM
If you want to correct it set up a new policy that runs the sudo jamf mdm command or sudo jamf manage and it should get it back.
I'd contact JAMF support as well as I could not find anyone else with this issue either in the forums.
Gabe Shackney
Princeton Public Schools
Posted on 12-17-2013 10:50 AM
@gshackney - did they give any indication of why this is happening? I'll try clearing the APN commands and resending but if this just keeps happening to machines that were once 'right', it will be a pain.
Posted on 12-17-2013 10:50 AM
If you want to correct it set up a new policy that runs the sudo jamf mdm command or sudo jamf manage and it should get it back.
I'll try this. Thank you.
Posted on 12-17-2013 10:51 AM
Here is my posts on the issue...
https://jamfnation.jamfsoftware.com/discussion.html?id=7301
Gabe Shackney
Princeton Public Schools
Posted on 12-17-2013 12:30 PM
Thank for the link gshackney. It was helpful.
I just want to let you know that I've been testing with two computers. One on my desk, and one remote. I do the same things on both, and one will enroll MDM, the other not. I've tried every way I can think of. I noticed two things about the system that will not MDM. 1) under inventory>certificates nothing is listed 2) under History>Management History there is nothing. No completed, pending, or failed.
What do I need to do to get his MDM enrolled? Everything else seems to work. When I do the verbose output I never see any mention of enrolling with MDM. Do I need to clear something off to accomplish this?
Posted on 12-17-2013 12:36 PM
I'm trying replacing the SSL cert on the Apache server. Just to see.
Posted on 12-18-2013 05:14 AM
That didn't help. I tried going to the machine and re-running the quickadd.pkg and still no MDM.
Posted on 12-18-2013 05:19 AM
I think they removed the jamf mdm command in version 9 of the JSS, but this was the only way I got them back.
I would call support, but let me know what the results are since I'm still seeing the issue. I have a policy that runs once a week that runs both the jamf mdm and jamf manage commands, the mdm one is the one that seems to fix it though and I don't know if there is another similar command that works in version 9.
Gabe Shackney
Princeton Public Schools
Posted on 12-18-2013 05:20 AM
Hi,
Yes I noticed no mdm command in 9. I tried manage. Yeah I'll probably have to open a ticket over this. Thank you, Aaron.
Posted on 01-15-2014 01:59 PM
Just as aside for those researching their own problems and stumbling upon this thread, I had these symptoms appearing due to intermittent interference from my content-filter/security-appliances. Can't hurt to double-check your ports and verify the traffic is actually getting through.
Apple, Unable to use APNs
http://support.apple.com/kb/TS4264
Apple, Troubleshooting Push Notifications
https://developer.apple.com/library/ios/technotes/tn2265/_index.html
Posted on 01-30-2014 10:34 AM
In our case re-enrolling with a new quickadd.pkg for the device solved the problem
Posted on 05-15-2015 11:30 AM
Researching this issue...cross-posting information that 10.7+ and a Recovery Partition are also needed
thanks Joel!
Posted on 03-23-2017 05:42 AM
@joelreid 3 years later and your reply came up in my searches. That technote page gave me the evidence I needed to prove that the APN servers were being blocked by our network security teams. Thank you JamfNation for retaining old information because it all becomes relevant again to someone in the future!