<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 1800 DNAC PNP not registering in Cisco Catalyst Center</title>
    <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4888829#M7262</link>
    <description>&lt;P&gt;Did you ever get this figured out? I'm having the same issue.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jul 2023 19:49:14 GMT</pubDate>
    <dc:creator>DanielPerez</dc:creator>
    <dc:date>2023-07-20T19:49:14Z</dc:date>
    <item>
      <title>Cisco 1800 DNAC PNP not registering</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4794895#M6617</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are currently evaluating a Cisco&amp;nbsp;AIR-AP1800S-E-K9, but this is failing to be claimed in Cisco DNA.&lt;/P&gt;&lt;P&gt;AP Running Image : 2.2.1.3&lt;BR /&gt;Primary Boot Image : 2.2.1.3&lt;BR /&gt;Backup Boot Image : 8.8.259.0&lt;/P&gt;&lt;P&gt;DHCP Option 43 configured to use:&amp;nbsp;option 43 ascii "5A1N;B2;I"DNA Server IP";J80;K4"&lt;/P&gt;&lt;P&gt;The Sensor goes away to be claimed, but fails with the following:&lt;/P&gt;&lt;P&gt;2023-03-15 17:01:05,974 - pnp.infra.network.HTTPConnClient - DEBUG - PNP requests with url: //ServerIP:443/pnp/WORK-REQUEST&amp;nbsp;&lt;BR /&gt;2023-03-15 17:01:05,997 - pnp.infra.network.HTTPConnClient - ERROR - Retrying Work-Info Request in 15 seconds...&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/usr/lib/pnp/infra/network/http_conn_client.py", line 253, in send_work_info_request&lt;BR /&gt;"pnp/WORK-REQUEST")&lt;BR /&gt;File "/usr/lib/pnp/infra/network/http_conn_client.py", line 149, in _send_request_helper&lt;BR /&gt;f = urllib2.urlopen(req, context=self.ctx, timeout=30)&lt;BR /&gt;File "/usr/lib/python2.7/urllib2.py", line 154, in urlopen&lt;BR /&gt;return opener.open(url, data, timeout)&lt;BR /&gt;File "/usr/lib/python2.7/urllib2.py", line 429, in open&lt;BR /&gt;response = self._open(req, data)&lt;BR /&gt;File "/usr/lib/python2.7/urllib2.py", line 447, in _open&lt;BR /&gt;'_open', req)&lt;BR /&gt;File "/usr/lib/python2.7/urllib2.py", line 407, in _call_chain&lt;BR /&gt;result = func(*args)&lt;BR /&gt;File "/usr/lib/python2.7/urllib2.py", line 1241, in https_open&lt;BR /&gt;context=self._context)&lt;BR /&gt;File "/usr/lib/python2.7/urllib2.py", line 1198, in do_open&lt;BR /&gt;raise URLError(err)&lt;BR /&gt;URLError: &amp;lt;urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] unknown error (_ssl.c:727)&amp;gt;&lt;BR /&gt;2023-03-15 17:01:21,018 - pnp.infra.Profile.1 - ERROR - Failed to send Work-Info request&lt;/P&gt;&lt;P&gt;We have the IP Address in the SAN Cert used in DNA, is there anything that could be stopping the sensor to be claimed?&lt;/P&gt;&lt;P&gt;Thanks, James&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 21:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4794895#M6617</guid>
      <dc:creator>JAMES WEST</dc:creator>
      <dc:date>2023-03-15T21:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 1800 DNAC PNP not registering</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4888829#M7262</link>
      <description>&lt;P&gt;Did you ever get this figured out? I'm having the same issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 19:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4888829#M7262</guid>
      <dc:creator>DanielPerez</dc:creator>
      <dc:date>2023-07-20T19:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 1800 DNAC PNP not registering</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4888862#M7267</link>
      <description>&lt;P&gt;There are plenty of reasons why certificates aren't valid. &amp;nbsp;Be sure to carefully follow instructions here:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/hardening_guide/b_dnac_security_best_practices_guide.html#task_zpl_4c2_rbb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/hardening_guide/b_dnac_security_best_practices_guide.html#task_zpl_4c2_rbb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Newer versions of DNA have a "generate CSR" button that should make the process much simpler (shown in the doc above)&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 21:12:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4888862#M7267</guid>
      <dc:creator>Preston Chilcote</dc:creator>
      <dc:date>2023-07-20T21:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 1800 DNAC PNP not registering</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4889437#M7274</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I had a similar problem a few days ago.&lt;/P&gt;
&lt;P&gt;In the past, I generated a System Certificate using OpenSSL as documented in the &lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/hardening_guide/b_dnac_security_best_practices_guide.html#task_zpl_4c2_rbb" target="_self"&gt;Security Best Practices Guide&lt;/A&gt;. Sensors were onboarded correctly into DNAC.&lt;/P&gt;
&lt;P&gt;More recently, I had to change my DNAC certificate to accommodate DNAC IP readdressing I had to do. This time I used the "Generate CSR" button from DNAC WebUI. And Sensors became unreachable from DNAC perspective.&lt;/P&gt;
&lt;P&gt;It appears that when using the "Generate CSR" button, the resulting CSR has the SANs DNS list reordered randomly. As stated in the Security Best Practices Guide, it says:&lt;/P&gt;
&lt;PRE&gt;The first DNS entry in the &lt;SPAN class="ph uicontrol"&gt;alt_names&lt;/SPAN&gt; section should contain &lt;SPAN class="ph"&gt;Cisco DNA Center&lt;/SPAN&gt;'s FQDN (&lt;CODE class="ph codeph"&gt;DNS.1 = FQDN-of-Cisco-DNA-Center&lt;/CODE&gt;).&lt;/PRE&gt;
&lt;P&gt;Cisco should fix this.&lt;/P&gt;
&lt;P&gt;After recreating a CSR using OpenSSL and uploading the new certificate into DNAC, Sensors were able to be fully functional again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hoe this helps.&lt;/P&gt;
&lt;P&gt;Sylvain.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 08:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4889437#M7274</guid>
      <dc:creator>Sylvain_Che</dc:creator>
      <dc:date>2023-07-21T08:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 1800 DNAC PNP not registering</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4898273#M7322</link>
      <description>&lt;P&gt;Thanks for the replies. I actually do have FQDN followed by the enterprise IP and node IP. Weirdly PNP works fine for switche's even my WLC but it fails during the onboarding process of AP's&amp;nbsp;C9120AXI-B to be exact.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 14:36:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/cisco-1800-dnac-pnp-not-registering/m-p/4898273#M7322</guid>
      <dc:creator>DanielPerez</dc:creator>
      <dc:date>2023-08-03T14:36:29Z</dc:date>
    </item>
  </channel>
</rss>

