Posted on 10-19-2021 09:13 AM
Hi Jamf Nation and happy JNUC 2021!
Today we released Jamf Pro 10.33 which includes support for Account-driven user enrollment for iOS/iPadOS. This workflow streamlines the user enrollment onboarding process and focuses on providing corporate access to BYO users while maintaining user privacy on their personal device.
We are also excited to announce Unified Endpoint Management Connector (UEMC) which is an integration between Jamf Threat Defense, Jamf Private Access, Jamf Data Policy and Jamf Pro for iOS/iPadOS. To learn more, please check out the Jamf blog post here.
This release also includes improvements to the Azure Active Directory integration within Jamf Pro, Recovery Lock password rotation, and a patch title filter option.
NOTE: Support for Jamf Imaging has been discontinued. With Jamf Pro 10.33, Jamf will no longer distribute Jamf Imaging as part of the Jamf Pro .dmg file.
Please read full release notes here.
Kaylee
Cloud Upgrade Schedule
Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 10.33 based on your hosted data region below.
Need assistance identifying the Hosted Data Region of your Jamf Cloud instance? Check out this guide to find out how.
Hosted Region | Begins | Ends |
ap-southeast-2 | Oct 29 at 1300 UTC | Oct 29 at 2200 UTC |
ap-northeast-1 | Oct 29 at 1500 UTC | Oct 29 at 2300 UTC |
eu-central-1 | Oct 29 at 2200 UTC | Oct 30 at 0800 UTC |
eu-west-2 | Oct 29 at 2300 UTC | Oct 30 at 0600 UTC |
us-east-1 | Oct 30 at 0400 UTC | Oct 30 at 1900 UTC |
us-east-1 sandbox | Oct 30 at 0000 UTC | Oct 30 at 0900 UTC |
us-west-2 | Oct 30 at 0700 UTC | Oct 30 at 2100 UTC |
Next Steps
For real-time messages about your upgrade, subscribe to alerts.
For information on what's new in Jamf Pro 10.33, please review the release notes.
Solved! Go to Solution.
Posted on 10-19-2021 11:32 AM
10.33.0 also fixes security issues, outlined here: https://docs.jamf.com/10.33.0/jamf-pro/release-notes/Resolved_Issues.html
Would be nice to include this fact in the "Jamf Pro Release" email-notifications and the release blog post instead of hiding it in "Resolved Issues"...
Thanks
Posted on 10-19-2021 10:23 AM
Wow, so Jamf is no longer going to support running a Jamf Pro server on macOS?
Posted on 10-19-2021 01:39 PM
Release notes say still supported under minimum system requirements. Available until removal in March 2022.
Pending removal note has been on the last few JAMF Pro version release notes.
"Support for using the Jamf Pro Installer for macOS will be discontinued in a future release (estimated removal date: March 2022)."
Posted on 10-20-2021 07:40 AM
Thanks for your mention @AntMac. To ensure we are the same page, we are sunsetting Jamf Imaging in 10.33.0, which is a workflow no longer supported. I believe your mention is more around an installer workflow. Deprecation of the installer for the macOS was announced 10.28.0, and we offer resources for migration https://docs.jamf.com/10.28.0/jamf-pro/release-notes/Deprecations_and_Removals.html . Please let us know if you have any additional questions. Thank you.
CC: @kaylee_carlson
Posted on 10-19-2021 10:29 AM
where do I fine the App to download?
Posted on 10-19-2021 10:46 AM
you can find in this link https://account.jamf.com/
Posted on 10-19-2021 10:50 AM
RIP Logout Hooks 😫
Posted on 10-19-2021 11:32 AM
10.33.0 also fixes security issues, outlined here: https://docs.jamf.com/10.33.0/jamf-pro/release-notes/Resolved_Issues.html
Would be nice to include this fact in the "Jamf Pro Release" email-notifications and the release blog post instead of hiding it in "Resolved Issues"...
Thanks
Posted on 10-19-2021 01:15 PM
This is an issue I have been repeating since Jamf management made this poor decision. There is no explanation why Jamf refuses to include this in notification emails, and it makes Mac admins jobs more difficult when a manager is not notified of what is changing.
Why should corporate management have to create a Jamf account just to read up on changes to the Jamf environment?
Jamf hasn't stopped sending us promotional emails. Why stop sending us useful information?
Posted on 10-20-2021 06:51 AM
Thank you for this feedback. We understand your concerns and will look to post resolved issues more clearly going forward.
Posted on 10-20-2021 06:52 AM
We appreciate this feedback and will work to make resolved issues part of our release communication going forward.
Posted on 10-19-2021 12:23 PM
Unfortunately this release does not seem to include mitigations for the recent Tomcat vulnerabilities. Assuming we'll see a 10.33.1 soon for that fix.
Posted on 10-20-2021 07:09 AM
Tomcat issues date back to 2020! Not only did I report the concern in our Linux server environment, Jamf support had provided a difficult method of replacing the JSS installed Tomcat with one from the Apache foundation. And this had to be done for each update.
The next several releases they were still using a Tomcat 6 months old with known vulnerabilities. Jamf Cloud is using 8.5.58 (2020-09-15), while https://tomcat.apache.org/tomcat-8.5-doc/changelog.html lists the latest version of 8.5.72 (2021-10-01)! Jamf's version is A YEAR OLD!
Posted on 10-21-2021 08:02 AM
This release, at least for on-prem users, does include Tomcat 8.5.71 (instead of 72) so the situation isn't as dire as it could be. But given the recent disclosures, was hoping this would include the latest update in the 8.5 series, if not move to a more recent branch.
Posted on 10-25-2021 08:37 AM
Hello,
Thank you for raising theses concerns up and continuing the discussion. I’ve reviewed the community feedback with our Engineering and Product Security teams. Our findings concluded with the following.
However, to remediate any potential risk, Jamf will be upgrading Tomcat in a near future release.
Please feel free to reach out with additional questions related to Tomcat 8.5.71. Happy to help!
Thank you,
Travis Cynor
Jamf Product Team
Posted on 10-21-2021 08:09 AM
With version 10.33 on prem i'm at this version of Tomcat.
Tomcat Version .................................... Apache Tomcat/8.5.71
Posted on 10-21-2021 08:48 AM
Exactly. We are still behind (i.e. not at 8.5.72) and vulnerable to the recent exploits.
Posted on 10-21-2021 07:52 AM
Careful with this one, folks! Make sure you have the latest server-tools and back up your database!
10.33 corrupted our database, and what normally takes 15 minutes cost me 3.5 hours because of an old server-tools binary! I had to restore the whole DB server virtual machine from backup.
A word to the wise....
Posted on 11-22-2021 06:52 AM
Has this been fixed yet? They sent an email saying it would be fixed on 11/17/21, but I have heard nothing yet.
11-22-2021 07:03 AM - edited 11-22-2021 07:04 AM
Hi @Sobchak! You'll find the current version (2.7.11) of Server Tool in Jamf Account (https://account.jamf.com/products/other/jamf-pro-server-tools). That's the one you should use to perform database backups if you're running Jamf Pro 10.33.
Please let us know if you have other questions.
Posted on 11-22-2021 08:18 AM
Do you just replace the jamf-pro.exe file?
I did that and have the following:
GUI version is 2.7.9
CLI version is 2.7.11
Is that ok to run the backup?
Thanks!
Posted on 11-22-2021 08:35 AM
@mvanstone Yes, you are good to run the backup.
Posted on 11-22-2021 08:32 AM
We are currently running 10.28 and were waiting for the database backup bug to be fixed before upgrading to 10.33. If we upgrade to 10.33 now will the new server tools be included or are we going to need to install those separately after the upgrade?
11-22-2021 08:37 AM - edited 11-22-2021 08:48 AM
@Sobchak The latest version of the server tools (2.7.11) is not included with 10.33. If you upgrade to 10.33 you will need to manually upgrade the server tools. You can do so following this link (https://account.jamf.com/products/other/jamf-pro-server-tools).
11-22-2021 10:06 AM - edited 11-22-2021 10:08 AM
Disregard - already answered above.... 😀