<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CAPWAP Certificate verified failed in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/capwap-certificate-verified-failed/m-p/4269786#M224963</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check if the &lt;STRONG&gt;1st&lt;/STRONG&gt;=&lt;STRONG&gt;&lt;FONT color="#008000"&gt;reply&lt;/FONT&gt;&lt;/STRONG&gt; of this thread is applicable to your case :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://community.cisco.com/t5/wireless/certificate-issue-joining-ap-to-vwlc/td-p/2036617" target="_blank"&gt;https://community.cisco.com/t5/wireless/certificate-issue-joining-ap-to-vwlc/td-p/2036617&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Jan 2021 18:29:16 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2021-01-10T18:29:16Z</dc:date>
    <item>
      <title>CAPWAP Certificate verified failed</title>
      <link>https://community.cisco.com/t5/wireless/capwap-certificate-verified-failed/m-p/4269717#M224956</link>
      <description>&lt;P&gt;I have this old AIR-AP1252G-A-K9 (which i downgraded from autonomous to light using the c1250-rcvk9w8-tar.124-21a.JA image) connected to a vWLC&amp;nbsp; AIR-CTVM-K9-8-0-152-0 running the trial license. They used to bind till yesterday when I cleared the vWLC config using "Recover-Config". Upon reconfiguring the vWLC they can't bind anymore due to expired certificates. I have already&amp;nbsp; entered the commands:&lt;/P&gt;&lt;P&gt;config ap cert-expiry-ignore mic enable&lt;/P&gt;&lt;P&gt;config ap cert-expiry-ignore mic enable&lt;/P&gt;&lt;P&gt;but to no avail. I've already done the same steps rolling back the clock on both devices, on 1 device and not the other, using NTP, but I keep getting the following errors:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Jan 10 09:31:45.999: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY&lt;BR /&gt;*Jan 10 09:31:45.999: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY&lt;BR /&gt;*Jan 10 09:31:56.007: %CAPWAP-3-ERRORLOG: Go join a capwap controller&lt;BR /&gt;*Jan 10 09:31:56.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.251 peer_port: 5246&lt;BR /&gt;*Jan 10 09:31:56.000: %CAPWAP-5-CHANGED: CAPWAP changed state to&lt;BR /&gt;*Jan 10 09:31:56.015: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed&lt;BR /&gt;*Jan 10 09:31:56.015: %CAPWAP-3-ERRORLOG: Certificate verification failed!&lt;BR /&gt;*Jan 10 09:31:56.015: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:326 Certificate verified failed!&lt;BR /&gt;*Jan 10 09:31:56.015: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.1.251&lt;BR /&gt;*Jan 10 09:31:56.015: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.1.251:5246&lt;BR /&gt;*Jan 10 09:31:56.015: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.1.251: Malformed Certificate&lt;BR /&gt;*Jan 10 09:31:56.015: %DTLS-5-SEND_ALERT: Send WARNING : Close notify Alert to 192.168.1.251:5246&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas on what to do next?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 19:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-certificate-verified-failed/m-p/4269717#M224956</guid>
      <dc:creator>juantovarm</dc:creator>
      <dc:date>2021-07-05T19:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP Certificate verified failed</title>
      <link>https://community.cisco.com/t5/wireless/capwap-certificate-verified-failed/m-p/4269786#M224963</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check if the &lt;STRONG&gt;1st&lt;/STRONG&gt;=&lt;STRONG&gt;&lt;FONT color="#008000"&gt;reply&lt;/FONT&gt;&lt;/STRONG&gt; of this thread is applicable to your case :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://community.cisco.com/t5/wireless/certificate-issue-joining-ap-to-vwlc/td-p/2036617" target="_blank"&gt;https://community.cisco.com/t5/wireless/certificate-issue-joining-ap-to-vwlc/td-p/2036617&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2021 18:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-certificate-verified-failed/m-p/4269786#M224963</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-01-10T18:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP Certificate verified failed</title>
      <link>https://community.cisco.com/t5/wireless/capwap-certificate-verified-failed/m-p/4270843#M225062</link>
      <description>&lt;P&gt;Thank you very much for your reply..&lt;/P&gt;&lt;P&gt;I had actually read that post before but that means getting my hands on a vWLC 7.3 OVA and CIsco's website has them as deferred. So, no luck there....&lt;/P&gt;&lt;P&gt;I ended up using another reply from that same post and it was to reinstall the original autonomous image via the emergency recovery method. That too took some tweaking because when i renamed the file to "default" in Windows, it showed up as&amp;nbsp; c1250-k9w7-tar.default.tar in the tftp filysystem, so the AP didn't recognize the image until I edited the name in linux.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 15:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-certificate-verified-failed/m-p/4270843#M225062</guid>
      <dc:creator>juantovarm</dc:creator>
      <dc:date>2021-01-12T15:00:01Z</dc:date>
    </item>
  </channel>
</rss>

