Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Know when the MDM certificate is removed from the Keychain #6434

Open
noahtalerman opened this issue Jun 29, 2022 · 5 comments
Open

Know when the MDM certificate is removed from the Keychain #6434

noahtalerman opened this issue Jun 29, 2022 · 5 comments
Labels
~customer request An enhancement requested by a Fleet customer customer-ufa ~legacy-interface-product-group Associated with the legacy "interface" product group. (No longer exists) story A user story defining an entire feature

Comments

@noahtalerman
Copy link
Member

noahtalerman commented Jun 29, 2022

Problem

An end user can turn off MDM features by removing the MDM certificate from the Keychain application (macOS). This means that the organization can no longer update macOS settings and macOS versions on this host.

More context is here in Slack (internal customer channel)

Goal

Add ability to know when the MDM certificate is removed from the Keychain.

Parent Epic

#397

@noahtalerman noahtalerman added ~customer request An enhancement requested by a Fleet customer story A user story defining an entire feature customer-ufa ~legacy-interface-product-group Associated with the legacy "interface" product group. (No longer exists) labels Jun 29, 2022
@noahtalerman noahtalerman self-assigned this Jun 29, 2022
@noahtalerman noahtalerman changed the title Add ability to know why hosts have undesired configuration See why hosts might have undesired configuration Jun 29, 2022
@noahtalerman
Copy link
Member Author

Think about writing a policy/query first.

@noahtalerman noahtalerman changed the title See why hosts might have undesired configuration Know how many hosts, and which hosts, have MDM issues Aug 4, 2022
@noahtalerman
Copy link
Member Author

@erikng if I recall correctly, you said that this would be the most valuable MDM issue to start with:

  • Know if/when a user deletes an MDM certificate.

Do you know of any osquery queries that could help us grab this information? This way Fleet could add this info to the Fleet API/UI.

@erikng
Copy link
Contributor

erikng commented Aug 12, 2022

It's probably going to take a few things.

Check the mdm profile plist settings to get the certificate name.

Check the user and system keychains for the presence of that cert.

@noahtalerman
Copy link
Member Author

UPDATE: this issue will be addressed in Q4 2022 (noahtalerman 2022-08-31).

@noahtalerman noahtalerman changed the title Know how many hosts, and which hosts, have MDM issues Know when the MDM certificate is removed from the Keychain Dec 23, 2022
@zayhanlon
Copy link
Contributor

@noahtalerman Removing the Slack thread link per customer request.

@noahtalerman noahtalerman removed their assignment Oct 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
~customer request An enhancement requested by a Fleet customer customer-ufa ~legacy-interface-product-group Associated with the legacy "interface" product group. (No longer exists) story A user story defining an entire feature
Projects
None yet
Development

No branches or pull requests

3 participants