<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failure to deploy SWIM certificate in Cisco Catalyst Center</title>
    <link>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870962#M7201</link>
    <description>&lt;P&gt;Do you have procedure on replacing the 4k certificate ?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jul 2023 12:33:59 GMT</pubDate>
    <dc:creator>Jaccobbchoi</dc:creator>
    <dc:date>2023-07-10T12:33:59Z</dc:date>
    <item>
      <title>Failure to deploy SWIM certificate</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4784004#M6540</link>
      <description>&lt;P&gt;We're having issues with telemetry between our DNAC appliance and our two HA pairs of 9800 WLCs.&amp;nbsp; In the past where telemetry has started acting up (resulting in all APs showing as "down" on heatmaps despite being "reachable" on the AP list, and "No Health" against each controller) a forced push of the telemetry settings has fixed things, but not this time.&lt;BR /&gt;&lt;BR /&gt;Drilling down into the configuration task failure notification reveals the following error:-&lt;/P&gt;&lt;H5&gt;&lt;STRONG&gt;Install of Swim Certificate&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;FONT color="#FF0000"&gt;FAILED&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H5&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Installation of SWIM Certificate initiated successfully&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Error occurred in ExecuteOnDeviceMessageHandler of NP: Error occured while executing the command 'do write memory'.Command Output : yes yes ^ % Invalid input detected at '^' marker.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Failing over the HA pair makes no difference.&lt;BR /&gt;Rebooting DNA Center makes no difference.&lt;BR /&gt;&lt;BR /&gt;DNAC&amp;nbsp;&lt;SPAN&gt;Version 2.3.3.6-70045&lt;BR /&gt;WLC IOS-XE version 17.3.6&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Does anyone else have any suggestions to try, or should we TAC it?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 11:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4784004#M6540</guid>
      <dc:creator>Martin Pritchard</dc:creator>
      <dc:date>2023-02-28T11:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Failure to deploy SWIM certificate</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870814#M7196</link>
      <description>&lt;P&gt;Same issue here. Same DNAC version except controller is running on 17.9.3&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 09:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870814#M7196</guid>
      <dc:creator>Jaccobbchoi</dc:creator>
      <dc:date>2023-07-10T09:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Failure to deploy SWIM certificate</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870828#M7197</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1471436"&gt;@Martin Pritchard&lt;/a&gt; what I did was updated the Telemetry settings in DNAC then reprovision and it worked. Make sure the telemetry update is successful before you reprovision&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 10:01:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870828#M7197</guid>
      <dc:creator>Jaccobbchoi</dc:creator>
      <dc:date>2023-07-10T10:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Failure to deploy SWIM certificate</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870949#M7199</link>
      <description>&lt;P&gt;I forgot about this query.&amp;nbsp; All fixed through TAC as the engineer had come across it before.&amp;nbsp; Problem was down to DNAC's new system certificate being 8K.&amp;nbsp; DNAC's happy with those, but 9800 controllers aren't.&amp;nbsp; Replacing this with a 4K certificate fixed it all.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 12:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870949#M7199</guid>
      <dc:creator>Martin Pritchard</dc:creator>
      <dc:date>2023-07-10T12:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Failure to deploy SWIM certificate</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870962#M7201</link>
      <description>&lt;P&gt;Do you have procedure on replacing the 4k certificate ?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 12:33:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4870962#M7201</guid>
      <dc:creator>Jaccobbchoi</dc:creator>
      <dc:date>2023-07-10T12:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Failure to deploy SWIM certificate</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4871135#M7203</link>
      <description>&lt;P&gt;The certificate was generated by us, and as it can be a bit fiddly to get all the tickboxes right I opened a copy of the 8K certificate up in SSL Shopper's CSR Decoder to get all the details in the right place when requesting the 4K one to replace it.&lt;/P&gt;&lt;P&gt;Location in DNAC: System -&amp;gt; Settings -&amp;gt; Trust &amp;amp; Privacy -&amp;gt; System Certificates&lt;/P&gt;&lt;P&gt;Some key takeaways:-&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Don't tick the "FQDN only" box&lt;/LI&gt;&lt;LI&gt;Common Name: IP address of the DNAC node (in our case it's not the one we always access it through, it's the address I think of the node itself, on the LAN, not the 192.168 internal cluster address), in our case this is automatically filled in.&lt;/LI&gt;&lt;LI&gt;Digest: sha512&lt;/LI&gt;&lt;LI&gt;Key Length: 4096&lt;/LI&gt;&lt;LI&gt;Key Usage: keyEncipherment&amp;nbsp; &amp;nbsp; digitalSignature&lt;/LI&gt;&lt;LI&gt;Extended Key Usage: serverAuth&amp;nbsp; &amp;nbsp; clientAuth&lt;/LI&gt;&lt;LI&gt;SanDNS: dnac.yourdomainname, pnpserver.yourdomainname, yourdnachostname.yourdomainname, yourdnacclustername.yourdomainname (in our case this was dnac.ourpublicdomain.gov.uk, pnpserver.ourdomain.local, oursite-dna-01.ourdomain.local, dnac.ourdomain.local, OURSITE-DNA.ourdomain.local)&lt;/LI&gt;&lt;LI&gt;SanIP: Internal cluster IP addresses (in our case 192.168.255.192, 192.168.255.194), IP address you access the whole system through, IP address of the node (the address you put in the Common Name above), for us this entry had four addresses altogether&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Obviously replace ourdomain, etc. with your actual domain details.&amp;nbsp; The above settings worked for us.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 15:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/failure-to-deploy-swim-certificate/m-p/4871135#M7203</guid>
      <dc:creator>Martin Pritchard</dc:creator>
      <dc:date>2023-07-10T15:02:08Z</dc:date>
    </item>
  </channel>
</rss>

