jss showing machine MDM Managed : NO

tkimpton
Valued Contributor II

Hi guys

I'm setting up configuration profiles for the first time and followed things here to get my jss setup:

https://jamfnation.jamfsoftware.com/article.html?id=111

The mdm is showing in Profiles preference pane but the machine in the jss keeps saying MDM Managed: No

I tried deleting the machine from the JSS and removing the JAMF framework and running recon again.

Has anyone else come across this?

1 ACCEPTED SOLUTION

tkimpton
Valued Contributor II

Shamefully I screwed up on certificates all ok

View solution in original post

5 REPLIES 5

justinrummel
Contributor III

I've seen this a couple of times on Linux installs. Can you confirm your configuration?

Sometimes the answer is 'wait 24 hours' and it magically works. I don't have a root cause at the moment.

- Justin

mscottblake
Valued Contributor

I had a terrible time with this at first as well. There are quite a few potential problems.

On the client computer, try to run "sudo jamf enroll". If it's still not managed, check the logs on your client computer. It should give some indication as to where it's failing.

Your server needs to have: - "Certificate Based-Communication" enabled - "Enable Push Notifications for OS X v10.7 or later clients" enabled - a SCEP-enabled Certificate Authority - a valid Push Notification Certificate

If you have all of these things and it's still not working, try renewing your CA certificate and then restarting Tomcat. I'm not sure if you would need to, but it might also help to renew your APN certificate.

tkimpton
Valued Contributor II

Thanks guys I think I will wait until Monday. I don't think I have SCEP-enabled Certificate Authority. But I'm not doing any iOS stuff.

mscottblake
Valued Contributor

If you are using the built-in CA, it is SCEP enabled. Even though you aren't doing any iOS management, Lion and Mountain Lion's configuration profiles are being handled in the same way. They both use APNs and both need SCEP-enabled CAs.

tkimpton
Valued Contributor II

Shamefully I screwed up on certificates all ok