Keychain entry being overwritten on Mojave

nycnewman
New Contributor III

Trying to find way to diagnose how / why a specific keychain entry is getting overwritten for a few of my users.

The symptom is that the user(s) complains that they are being asked for a Wifi password to our corporate network. This is being pushed by a JAMF policy. However for one user I remove MDM and re-added. I see the keychain correctly getting added with correct value but shortly afterwards the actual password in the Keychain was changed by something to an incorrect value. User can access the Wifi until the machine sleeps and need to reconnect, at which point they get asked for password.

I have gone through configuration profiles and policies and do not see anything that should change (apart from Wireless push).

Are there good ways to enable debugging or auditing so I can track what is making this change. Either JAMF is overwriting or an iCloud sync.

Thoughts? Suggestions?

1 ACCEPTED SOLUTION

nycnewman
New Contributor III

This was ultimately resolved. Users had visited a standalone corporate site which used same SSID but different password. This got into their iCloud Keychain and this was overwriting the MDM set password. Deleting entry from iCloud KeyChain stopped the issue.

View solution in original post

1 REPLY 1

nycnewman
New Contributor III

This was ultimately resolved. Users had visited a standalone corporate site which used same SSID but different password. This got into their iCloud Keychain and this was overwriting the MDM set password. Deleting entry from iCloud KeyChain stopped the issue.