<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL Cert error in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220448#M18801</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The password is the password you used when you created the request. This PW is encrypted in your "mykey.pem" file, or whatever you named it. If these dont match you will get an error. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 06 Jun 2009 03:39:46 GMT</pubDate>
    <dc:creator>George Stefanick</dc:creator>
    <dc:date>2009-06-06T03:39:46Z</dc:date>
    <item>
      <title>SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220447#M18800</link>
      <description>&lt;P&gt;we are following this doc:&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00806e367a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00806e367a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are at the part that wants us to:&lt;/P&gt;&lt;P&gt;6. Combine the CA.pem certificate with the private key, and then convert the file to a .pem file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue this command in the OpenSSL application:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    openssl&amp;gt;pkcs12 -export -in CA.pem -inkey mykey.pem -out CA.p12 -clcerts &lt;/P&gt;&lt;P&gt;     -passin pass:check123 -passout pass:check123&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we type it in we get this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; pass:fakepassword-1 -passout pass:fakepassword-1&lt;/P&gt;&lt;P&gt;Loading 'screen' into random state - done&lt;/P&gt;&lt;P&gt;No certificate matches private key&lt;/P&gt;&lt;P&gt;unable to write 'random state'&lt;/P&gt;&lt;P&gt;error in pkcs12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;were not sure whats wrong. What password should I be using? Should it be the challenge password is step 3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also we picked Microsoft as our server in the enrollment tool part. Could this be part of the problem? If so what should we have picked&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 00:41:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220447#M18800</guid>
      <dc:creator>Starthorn</dc:creator>
      <dc:date>2021-07-04T00:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220448#M18801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The password is the password you used when you created the request. This PW is encrypted in your "mykey.pem" file, or whatever you named it. If these dont match you will get an error. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jun 2009 03:39:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220448#M18801</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2009-06-06T03:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220449#M18802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've noted on the Verisign page from another Cisco device query (ACS 3.2) that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;..step..&lt;/P&gt;&lt;P&gt;12. Go to Enrollment. When enrolling for the SSL Certificate you will be asked to choose a server vendor, choose Apache. This will allow a certificate that is compatible with the Cisco ACS.&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if anyone knows what Vendor type would be appropriate for a Cisco 4400 series controller. Was about to send Verisign an email but thought this may be "vendor" specific.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2009 19:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220449#M18802</guid>
      <dc:creator>rcsu-it</dc:creator>
      <dc:date>2009-06-24T19:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220450#M18803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just tried picking Apache. When I try to merge the files I get a new error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Loading 'screen' into random state - done&lt;/P&gt;&lt;P&gt;unable to write 'random state'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 16:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220450#M18803</guid>
      <dc:creator>Starthorn</dc:creator>
      <dc:date>2009-06-25T16:09:18Z</dc:date>
    </item>
    <item>
      <title>SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220451#M18804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;anyone ever come up with the solution to this?&amp;nbsp; i'm stuck on the same step with the same error.&amp;nbsp; i have copied the device, intermediate, and root cert files (using proper delimiters and in proper order) into and All-certs.pem and ran the command &lt;STRONG style="border-collapse: collapse; font-size: 10pt; list-style: none;"&gt;pkcs12 -export -in All-certs.pem -inkey mykey.pem -out CA.p12 -clcerts&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;i did not use the -pass options as no password was ever set during the private key generation step.&amp;nbsp; i get the error &lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;No certificate matches private key&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;all files are right in the bin folder with the openssl executable.&amp;nbsp; i know openssl is finding them because if i take them out of that folder i get file not found errors.&amp;nbsp; i have also verified the files are a matching set by comparing the md5 hashes with the following commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;x509 -noout -modulus -in All-certs.pem | openssl md5&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;rsa -noout -modulus -in mykey.pem | openssl md5&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jan 2013 20:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220451#M18804</guid>
      <dc:creator>bgoulet00</dc:creator>
      <dc:date>2013-01-25T20:11:42Z</dc:date>
    </item>
    <item>
      <title>SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220452#M18805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well the password is mandatory.. also that error means that the private key does not match or is not found in the same directory your running the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Combine the All-certs.pem certificate with the private key that you generated along with the CSR (the private key of the device certificate, which is mykey.pem in this example), and save the file as &lt;EM&gt;final.pem&lt;/EM&gt;. &lt;/P&gt;&lt;P&gt;Issue these commands in the OpenSSL application in order to create the All-certs.pem and final.pem files:&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;PRE&gt;openssl&amp;gt;&lt;STRONG&gt;pkcs12 -export -in All-certs.pem -inkey mykey.pem 
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -out All-certs.p12 -clcerts -passin pass:check123 
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -passout pass:check123&lt;/STRONG&gt;
&amp;nbsp; 
openssl&amp;gt;&lt;STRONG&gt;pkcs12 -in All-certs.p12 -out final-cert.pem 
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -passin pass:check123 -passout pass:check123&lt;/STRONG&gt;
&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note: &lt;EM&gt;In this command, you must enter a password for the parameters -passin and -passout. The password that is configured for the -passout parameter must match the certpassword parameter that is configured on the WLC. In this example, the password that is configured for both the -passin and -passout parameters is check123. &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;final.pem is the file that we need to download to the Wireless LAN Controller&lt;/STRONG&gt;. The next step is to download this file to the WLC.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jan 2013 20:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220452#M18805</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-25T20:39:42Z</dc:date>
    </item>
    <item>
      <title>SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220453#M18806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can the -passin parameter be left out?&amp;nbsp; we didn't set a password when generating the private key so there is no argument to supply to -passin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the -passin command is required and private key must have a password, is there a way to add the password after the fact or do i have to go through the generation process again?&amp;nbsp; will the lack of password use cause this error or is it just a requirement for load onto the WLC at the end?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it was my understanding that the error meant the &lt;SPAN style="font-size: 10pt;"&gt;private key does not match or is not found in the same directory but as i mentioned above, when the files are not in bin, i get error that the file can't be found or cannot be opened.&amp;nbsp; those errors go away when i drop the files in the bin directory so that tells me openSSL is seeing them.&amp;nbsp; the only way i know to determain if the private key matches is with the md5 hash and that test passes so i'm not sure what else the problem could be.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jan 2013 20:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220453#M18806</guid>
      <dc:creator>bgoulet00</dc:creator>
      <dc:date>2013-01-25T20:51:38Z</dc:date>
    </item>
    <item>
      <title>SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220454#M18807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can the -passin parameter be left out? we didn't set a password when generating the private key so there is no argument to supply to -passin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No it can't.... you don't need to setup one when your are doing the CSR.... this is just to put one in so when you upload it to the WLC the WLC will take it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2013 03:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220454#M18807</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-26T03:36:16Z</dc:date>
    </item>
    <item>
      <title>SSL Cert error</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220455#M18808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you follow all the steps correctly it should work, you cannot leave the password as Scott indicated because it is required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 16:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220455#M18808</guid>
      <dc:creator>Kayle Miller</dc:creator>
      <dc:date>2013-01-28T16:10:01Z</dc:date>
    </item>
    <item>
      <title>Hi there, Did you manage to</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220456#M18809</link>
      <description>&lt;P&gt;Hi there, Did you manage to resolve this?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 15:38:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220456#M18809</guid>
      <dc:creator>Tim Davies</dc:creator>
      <dc:date>2014-09-02T15:38:36Z</dc:date>
    </item>
    <item>
      <title>Here is my response to the</title>
      <link>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220457#M18810</link>
      <description>&lt;P&gt;Here is my response to the TAC Engineer at the time:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sent: Tuesday, September 01, 2009 3:08 PM&lt;/P&gt;&lt;P&gt;To: Vijaya Baliwada (vbaliwad)&lt;/P&gt;&lt;P&gt;Subject: Re: Sev3 SR 612355487 : WLC WebAuth Cert Issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vijaya,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm glad to inform you that by using the X.509 certificate response file from Verisign and after trying a combination of the entity certificate, intermediate certificate AND the proper X.509 Base-64 bit format Verisign Root certificate the commands in the documentation worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our main issue was incorrectly using the PKCS#7 certificate from Verisign. The openssl commands worked instantly using x.509. We also had difficulty obtaining the correct root certificate from Verisign. We obtained the browser DER formatted root from internet explorer and exported it from IE to an x.509 Base-64 format. Then did the combination described above and added it to webauth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 02:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssl-cert-error/m-p/1220457#M18810</guid>
      <dc:creator>rcsu-it</dc:creator>
      <dc:date>2014-09-25T02:38:08Z</dc:date>
    </item>
  </channel>
</rss>

