<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 5520 Upgrade Issue in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154485#M196979</link>
    <description>&lt;P&gt;will try and let you know&lt;/P&gt;</description>
    <pubDate>Mon, 21 Sep 2020 08:32:13 GMT</pubDate>
    <dc:creator>kishen32</dc:creator>
    <dc:date>2020-09-21T08:32:13Z</dc:date>
    <item>
      <title>WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154466#M196973</link>
      <description>&lt;P&gt;Hi guys, i am having a weird issue post upgrade of HA WLC 5520 from 8.1.102.0 to 8.5.164.0. The previous active unit is standby and current active box i do see APs associated. The problem is when i failover the WLC, the actual active unit unable to get the APs associated. When i see the error logs, i see as below. Is this related to come SSL cert missing in the WLCs, since i see some certificate present on the standby unit but not in the active unit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*spamApTask0: Sep 21 10:08:52.561: %DTLS-3-PKI_ERROR: [PA]openssl_dtls.c:547 PKI initialization error : Certificate initialization failed&lt;BR /&gt;*spamApTask0: Sep 21 10:08:52.561: %LOG-3-Q_IND: [PA]sshpmcert.c:897 Accessing certificate table before initialization&lt;BR /&gt;*spamApTask0: Sep 21 10:08:52.561: %SSHPM-3-CERT_TABLE_INVALID: [PA]sshpmcert.c:897 Accessing certificate table before initialization&lt;BR /&gt;*spamApTask2: Sep 21 10:08:51.608: %CAPWAP-3-DTLS_DB_ERR: [PA]capwap_ac_sm.c:9726 78:48:59:de:34:04: Failed to create DTLS connection for AP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did some checks online and the closest i see if the below solution, but it looks like not applicable to my scenario. The WLC time looks ok to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/wireless-and-mobility/ap-can-t-join-dtls-connection-closed-by-controller/td-p/1871401" target="_blank"&gt;https://community.cisco.com/t5/wireless-and-mobility/ap-can-t-join-dtls-connection-closed-by-controller/td-p/1871401&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/wireless-and-mobility/ap-s-wont-connect-to-5508-wlc-after-update-to-8-3-143-pki/td-p/3690280" target="_blank"&gt;https://community.cisco.com/t5/wireless-and-mobility/ap-s-wont-connect-to-5508-wlc-after-update-to-8-3-143-pki/td-p/3690280&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i see the certificate, the output as below on the actual active unit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Cisco Controller) &amp;gt;show certificate all&lt;/P&gt;&lt;P&gt;--------------- Verification Certificates ---------------&lt;/P&gt;&lt;P&gt;-------------- Identification Certificates --------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;(Cisco Controller) &amp;gt;show certificate summary&lt;BR /&gt;Web Administration Certificate................... Locally Generated&lt;BR /&gt;Web Authentication Certificate................... Locally Generated&lt;BR /&gt;Certificate compatibility mode:.................. off&lt;BR /&gt;Lifetime Check Ignore for MIC ................... Disable&lt;BR /&gt;Lifetime Check Ignore for SSC ................... Disable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While this is how it looks in the standby unit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Cisco Controller) &amp;gt;show certificate all&lt;/P&gt;&lt;P&gt;--------------- Verification Certificates ---------------&lt;/P&gt;&lt;P&gt;-------------- Identification Certificates --------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;(Cisco Controller) &amp;gt;show certificate summary&lt;BR /&gt;Web Administration Certificate................... 3rd party&lt;BR /&gt;Web Authentication Certificate................... Locally Generated&lt;BR /&gt;Certificate compatibility mode:.................. off&lt;BR /&gt;Lifetime Check Ignore for MIC ................... Disable&lt;BR /&gt;Lifetime Check Ignore for SSC ................... Disable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any lead from you guys as this point i am out of ideas and the device is out of contract, hence i can't raise a tac case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. Tried below config as well, no luck&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;config ap cert-expiry-ignore mic disable&lt;BR /&gt;config ap cert-expiry-ignore ssc disable&lt;/P&gt;&lt;P&gt;config auth-list ap-policy ssc disable&lt;BR /&gt;config certificate ssc hash validation enable&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 19:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154466#M196973</guid>
      <dc:creator>kishen32</dc:creator>
      <dc:date>2021-07-05T19:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154473#M196974</link>
      <description>&lt;P&gt;The APs are not joining the 8.5.X.X controller?&lt;BR /&gt;What model is the AP?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154473#M196974</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2020-09-21T08:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154474#M196975</link>
      <description>The cert you show is only for web admin. I’m assuming you didn’t have any issues with failover before you upgraded and not units were able to associate AP’s?  This is what I would do, but again, others might handle it differently. I would take the wlc that is not working out and factory default it. Then I would go through the startup wizard and configure the basic settings. Then I would follow the guide eon replacing the primary controller in SSO and see if that fixes the issue. I have done this a few times when one of the units would fail and or had an issue with one of the units. Once you enable SSO on the one you factory default, it will sync the configuration from the existing and then you can try the fail over once both show up and sync. &lt;BR /&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154474#M196975</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-09-21T08:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154475#M196976</link>
      <description>&lt;P&gt;Combination of 2800 and 2700, it can join on the standby unit when i failover from active to standby, but not associating to the actual active unit when i make it primary&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154475#M196976</guid>
      <dc:creator>kishen32</dc:creator>
      <dc:date>2020-09-21T08:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154481#M196977</link>
      <description>&lt;P&gt;Console into the AP and reboot the AP.&amp;nbsp;&lt;BR /&gt;Post the entire boot-up process.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154481#M196977</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2020-09-21T08:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154484#M196978</link>
      <description>&lt;P&gt;What about the license, from the actual active unit i can't see the license file which i had previously. i added manually and can see it. Not sure if the box it self had crashed.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154484#M196978</guid>
      <dc:creator>kishen32</dc:creator>
      <dc:date>2020-09-21T08:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154485#M196979</link>
      <description>&lt;P&gt;will try and let you know&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 08:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154485#M196979</guid>
      <dc:creator>kishen32</dc:creator>
      <dc:date>2020-09-21T08:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154667#M196980</link>
      <description>&lt;P&gt;First - did you follow the release note recommendations (always read the release notes carefully).&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr6_ircm.html#software-rel-types-and-recommendations_85_mr56" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr6_ircm.html#software-rel-types-and-recommendations_85_mr56&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you were upgrading from 8.1.102.0 you should have upgraded to 8.2.166.0 or 8.2.170.0 first and then from there to 8.5.164.0 - which by the way is still only recommended/supported if you need IRCM feature otherwise you're recommended to use 8.5.161.0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But regardless of all that I agree with Scott to rebuild from factory default.&lt;/P&gt;&lt;P&gt;If public certificates are missing you'll need to re-install them - simple.&lt;/P&gt;&lt;P&gt;If self-signed certificates are missing/corrupted (have seen that happen on upgrade before) then you'll need to re-generate them.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 13:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/4154667#M196980</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2020-09-21T13:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224483#M277723</link>
      <description>&lt;P&gt;I have a handful of these APs with no certificates installed, and none of the guides I've found say anything about how to install or generate certificates, why they're needed, etc.&amp;nbsp; Can someone help?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 16:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224483#M277723</guid>
      <dc:creator>mtexter</dc:creator>
      <dc:date>2024-11-14T16:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224491#M277725</link>
      <description>&lt;P&gt;Certificates are required for the AP to trust the controller and vice versa.&amp;nbsp; You have AP's with no certificates or expired certificates?&amp;nbsp; Have you tried to search the forum for answers to your questions?&amp;nbsp; You might as well open a new thread and post exactly what AP's you have, what controller and what code.&amp;nbsp; Also show log's that can help identify the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 17:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224491#M277725</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2024-11-14T17:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224504#M277730</link>
      <description>&lt;P&gt;No APs at all currently, just looking to upgrade the AireOS on a WLC5520, currently at 8.10.130.0, getting the age-old "failed to validate signature!" error after transferring the image.&amp;nbsp; Been looking all over old forum posts and tried everything from this one&amp;nbsp;&lt;A href="https://community.cisco.com/t5/wireless-mobility-blogs/wlc-5520-or-8540-upgrade-failing-with-failure-while-validating/ba-p/3102518" target="_blank"&gt;https://community.cisco.com/t5/wireless-mobility-blogs/wlc-5520-or-8540-upgrade-failing-with-failure-while-validating/ba-p/3102518&lt;/A&gt;&amp;nbsp;- no joy.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Issue definitely appears to stem from lack of certificates which is why I necroed this thread.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I can upload logs / output from any commands you'd like to see, just let me know&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 17:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224504#M277730</guid>
      <dc:creator>mtexter</dc:creator>
      <dc:date>2024-11-14T17:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224559#M277732</link>
      <description>&lt;P&gt;What ap models? No ap's, so basically you just have a 5520 you want to test with?&amp;nbsp; The link you posted is correct, just use http not https.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 19:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224559#M277732</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2024-11-14T19:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224571#M277734</link>
      <description>&lt;P&gt;Correct.&amp;nbsp; We're getting these ready for a customer who I assume will install their own certificates once they get to site.&amp;nbsp; We just wanted to update AireOS and ensure full functionality before shipping.&lt;BR /&gt;&lt;BR /&gt;Regarding the link I posted, I don't see any difference in the pages if I use https:// vs http://&amp;nbsp; the content is exactly the same.&amp;nbsp; In fact if I use http it just redirects to https.&amp;nbsp; Am I missing something?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 19:48:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224571#M277734</guid>
      <dc:creator>mtexter</dc:creator>
      <dc:date>2024-11-14T19:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224575#M277735</link>
      <description>&lt;P&gt;I also found the &lt;FONT face="courier new,courier"&gt;config certificate generate&lt;/FONT&gt; command which looked like it was going to create new certs for webadmin and webauth, the other options were to create certificate signing requests, which i'm not sure what to do with.&amp;nbsp; In any case, those commands appear to have done nothing, even after a system reset.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 19:53:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224575#M277735</guid>
      <dc:creator>mtexter</dc:creator>
      <dc:date>2024-11-14T19:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Upgrade Issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224760#M277740</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/496409"&gt;@mtexter&lt;/a&gt;&amp;nbsp;wrote :&amp;nbsp;&lt;EM&gt;Issue definitely appears to stem from lack of certificates which is &lt;U&gt;&lt;STRONG&gt;why I necroed this thread.&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Please start a new thread and describe the problem from scratch , include screenshot(s) from what you are seeing (e.g.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 07:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-upgrade-issue/m-p/5224760#M277740</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-11-15T07:21:24Z</dc:date>
    </item>
  </channel>
</rss>

