unable to enable MDM for user account

scharman
New Contributor

Hi guys

Having an issue enabling MDM for the local user account, this is the error I get via the terminal

Enabling MDM at the user level...
Error installing the user level mdm profile: profiles install for file:'/Library/Application Support/JAMF/270DAF70-6EC3-4A0B-A010-8C6731B28B04.mobileconfig' and user:'scharman' returned -915 (Unable to contact the SCEP server at “https://casper.staff.iinet.net.au:8443//CA/SCEP”.)
Problem installing MDM profile.
Problem detecting MDM profile after installation.

any idea?
cheers

6 REPLIES 6

dmw3
Contributor III

@scharman I am getting a similar error when trying to force install a config profile from the terminal using:

sudo jamf manage

I looked more into SCEP and found that I had to find or setup a SCEP server for our environment.

Still trying to do this. At this point I am unable to push config profiles out from the JSS, scope is ok and I can manually add the config profile on the client computer and it works, just cannot send due to no SCEP available.

robby_barnes
New Contributor III

I have had this problem on a couple of machines in my environment as well. For me just going in to terminal on that machine (or Remote Desktop) and doing "sudo profiles -D", which will clear out all management profiles seemed to solve the problem. It would enroll just fine after that.

The weird part is that all of the machines I was doing this with did not have any profiles on them. Still, the terminal command seemed to flush something out of the system that was getting stuck, and it seemed to resolve them.

Note: if you're doing it from Apple Remote desktop, you need to run it as root still, but you'll want to do "profiles -D -f" so that it doesn't prompt you with the warning.

Not sure if this works in every case, but it's worked in my environment several times.

bmortens115
New Contributor III
New Contributor III

any resolution on this? I am getting the same error message on a new JSS 9.81. I renewed the SSL cert then rebooted Tomcat, then renewed the APNS cert

easyedc
Valued Contributor II

Anyone come up with anything on this. I thought it was SSL related, renewed self signed cert, tried external CA cert, tried self-signed again and still getting this problem.

donmontalvo
Esteemed Contributor III

Seems to come and go...last week mucho SCEP/MDM issues...turn your back for a couple days...everything is fine...rinse, lather, and repeat.

--
https://donmontalvo.com

ChicagoGuy1984
New Contributor III

Well, fast forward month ago.... and

Running 10.11.6 and JSS 9.96 and still getting this issue. Did anybody have a solid solution for this?

... side note, I did notice this working just fine last month , as @donmontalvo said, it comes and goes.... sort of like "Apple Gives and Apple Takes away"

Thanks,
Marek