

The reason for this is during the configuration of the JSS self-hosted deployment option, an organization is responsible for ensuring that SSL/TLS certificates are properly deployed before enabling this setting. The ‘JSS Settings’ section of the document outlines additional settings, and we’ll look at one: “Enable SSL certificate verification.” Note that this setting is not on by default. JAMF has outlined the steps to secure JSS deployment here: In particular, it is important to note that with the self-hosted solution organizations are responsible for SSL certificate generation for use with the JSS. When choosing a deployment model for Casper Suite there are two basic solutions: Self-hosted or a solution hosted in the JAMF Cloud where an organization would configure their instance of the JSS.
#What is jamf software software
This suite of tools includes software that will help track inventory, manage devices, implement security policies, and deployment of software and scripts to end point Apple product clients. Specifically for this post, we'll be focusing on JAMF’s Casper Suite and deploying a JSS. JAMF Software encompasses a number of solutions for fleet management of Apple products, including their own Apple MDM. We alerted JAMF Software and it has been responsive with its next steps to address the issue.

Organizations should make sure they have enabled a very simple configuration setting, e.g. We came across a default setting in JAMF Software Server (JSS), which we believe can put companies leveraging the solution at risk.
