
What is jamf recon pro#
The good news for all Jamf Cloud users is that all this is taken care of by some Cloud wizards at Jamf:īut wait a second, do I really need to upload my own SSL cert to Jamf Pro when I’m using an on-prem server? Do I have to buy one? Note: although issues like this might be related to the SSL certificate itself, it's also possible that the uploaded SSL cert is missing an Intermediate CA or Tomcat was not rebooted after uploading he new cert.

Especially when a new certificate was uploaded. Unless something bad happened to Tomcat, it’s often related to the SSL certificate. I’ve seen situation where people panic when suddenly all communication with their (on-prem) Jamf Pro server stopped. SSL cert not valid? No communication! See what happens for instance with a ‘sudo jamf policy’ or ‘sudo jamf recon’ if the SSL cert of the Jamf Pro server is expired or invalid (wrong FQDN for instance): Just like with every possible HTTPS/SSL connection you can imagine.
What is jamf recon mac#
Whenever a Mac or iOS device contacts the Jamf Pro server it also verifies the SSL certificate. In my case the DST Root CA, aka Let’s Encrypt:īut, when we, as a human being, see the below (when attempting to login to Jamf Pro, or when a user tries to enroll a device via User Initiated Enrolment), we know there is something wrong!Īll straight forward I guess, but what about devices interacting with Jamf Pro? Well, exactly the same. Someone, trusted by the entire world, has verified the identity of this server and issued a certificate to proof it. Whether that is a certificate for the specific FQDN or a wildcard cert, it doesn’t matter. However, without the intend to state the obvious, what does the SSL Certificate on Tomcat actually do? Well, nothing more than providing proof of the identity of the server. I presume that it’s safe enough to assume we all understand the importance of HTTPS and SSL. However, there might be some confusion regarding its importance in view of device communication. This might be the most straight forward one to discuss.

What is jamf recon full#
The goal of this post is mainly to differentiate the variety of certificates, and their purpose, not to give you a full in-depth discussion of each of one.ĭepending on how you use Jamf Pro, what functionality you use and the different integrations you add to the JPS, the types of certificates which cross your path may vary. No, I’m not a certificate expert, just a guy who needs them from time to time, no way around it! So I decided to dedicate this post to the different certificates you might come across when using Jamf Pro.
