<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate unknown alert in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315542#M227822</link>
    <description>&lt;P&gt;I have NOW! I feel a&amp;nbsp;migraine headache coming on.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Mar 2021 15:59:11 GMT</pubDate>
    <dc:creator>David Ritter</dc:creator>
    <dc:date>2021-03-29T15:59:11Z</dc:date>
    <item>
      <title>Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314546#M227745</link>
      <description>&lt;P&gt;I have 4 AIR-CAP3502i-A-K9's that received Fatal reports from WLC 8.5.164.0.&amp;nbsp; I have 7 others still associating.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Mar 26 14:01:47.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: x.x.x.x peer_port: 5246&lt;BR /&gt;*Mar 26 14:01:47.210: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from x.x.x.x&lt;BR /&gt;*Mar 26 14:01:47.210: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to x.x.x.x:5246&lt;/P&gt;&lt;P&gt;How do I regen or create a new Cert?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 20:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314546#M227745</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2021-07-05T20:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314584#M227748</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- On the AP check the certificate with :&amp;nbsp;&lt;STRONG&gt;AP# show crypto pki certificates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;M.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 16:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314584#M227748</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-26T16:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314600#M227750</link>
      <description>&lt;P&gt;unfortunately there is no Show Crypto cmd but I can view them all in show tech..&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is:&lt;/P&gt;&lt;P&gt;crypto pki certificate chain cisco-m2-root-cert&lt;BR /&gt;certificate ca 01...&lt;/P&gt;&lt;P&gt;crypto pki certificate chain Cisco_IOS_M2_MIC_cert&lt;BR /&gt;certificate ca 02...&lt;/P&gt;&lt;P&gt;crypto pki certificate chain airespace-old-root-cert&lt;BR /&gt;certificate ca 00...&lt;/P&gt;&lt;P&gt;crypto pki certificate chain airespace-new-root-cert&lt;BR /&gt;certificate ca 00..&lt;/P&gt;&lt;P&gt;crypto pki certificate chain airespace-device-root-cert&lt;BR /&gt;certificate ca 03...&lt;/P&gt;&lt;P&gt;crypto pki certificate chain cisco-root-cert&lt;BR /&gt;certificate ca 5FF87B282B54DC8D42A315B568C9ADFF..&lt;/P&gt;&lt;P&gt;crypto pki certificate chain Cisco_IOS_MIC_cert&lt;BR /&gt;certificate 15B7774C000000055EC7...&lt;/P&gt;&lt;P&gt;certificate ca 6A6967B3000000000003&lt;/P&gt;&lt;P&gt;end list..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 16:27:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314600#M227750</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2021-03-26T16:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314775#M227764</link>
      <description>&lt;P&gt;Certificate expired for some ap&lt;/P&gt;</description>
      <pubDate>Sat, 27 Mar 2021 02:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314775#M227764</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-03-27T02:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314794#M227766</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;crypto pki certificate chain cisco-m2-root-cert&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;certificate ca 01...&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Check if any expiration dates are mentioned too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Mar 2021 06:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4314794#M227766</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-27T06:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315127#M227789</link>
      <description>&lt;P&gt;Have you read &lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html&lt;/A&gt; and followed the instructions carefully?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you forgot to apply the config to allow APs or WLC (you didn't mention WLC model but they can also be affected) with expired cert then you'll have to turn off NTP, set the time back to before cert(s) expired, apply the config workaround on WLC, allow all APs to rejoin and get the update, then put NTP on again.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 09:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315127#M227789</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2021-03-28T09:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315432#M227813</link>
      <description>&lt;P&gt;ON WLC CLI&amp;gt;&amp;nbsp;&lt;SPAN&gt;config ap cert-expiry-ignore mic enable&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 12:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315432#M227813</guid>
      <dc:creator>superego</dc:creator>
      <dc:date>2021-03-29T12:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315542#M227822</link>
      <description>&lt;P&gt;I have NOW! I feel a&amp;nbsp;migraine headache coming on.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 15:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315542#M227822</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2021-03-29T15:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315551#M227823</link>
      <description>&lt;P&gt;that solved the 4 3502's attached to the 5508 on 8.5.164.0 . reporting the&amp;nbsp;cert unknown.&lt;/P&gt;&lt;P&gt;not the 1810w reporting&amp;nbsp;Discovery response from MWAR ''running version 0.0.0.0 is rejected&lt;/P&gt;&lt;P&gt;or the 3 1852s attached to the 5520 also reporting: Discovery response from MWAR ''running version 0.0.0.0 is rejected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not yet been thru all the previous replies..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you the 3502's comprised an entire site..&amp;nbsp; so good they are alive again.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 16:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315551#M227823</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2021-03-29T16:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315570#M227824</link>
      <description>&lt;P&gt;I never upgraded to 8.5.164 as I see the warning "&lt;SPAN&gt;This Image/Release is used ONLY for C9800 IRCM Compatibility."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you try upgrading to&amp;nbsp;&lt;/SPAN&gt;8.5.171?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 16:45:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315570#M227824</guid>
      <dc:creator>superego</dc:creator>
      <dc:date>2021-03-29T16:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315632#M227826</link>
      <description>&lt;P&gt;understood.&amp;nbsp; however, I have a 9800-40 sitting in the wings waiting to take command once it gets vlan interfaces to support the entire campus.&amp;nbsp; I'm combining two sites into one and need more elbow room.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 18:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4315632#M227826</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2021-03-29T18:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate unknown alert</title>
      <link>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4316113#M227842</link>
      <description>&lt;P&gt;Note that there is a new IRCM release 8.5.176.0 which Cisco said on webinar last week resolves a number of bugs in 8.5.164.0 and should also have all the fixes which went into 8.5.171.0 so suggest you upgrade to that for a start:&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/286284738/type/280926587/release/8.5IRCM" target="_blank"&gt;https://software.cisco.com/download/home/286284738/type/280926587/release/8.5IRCM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/282600534/type/280926587/release/8.5IRCM" target="_blank"&gt;https://software.cisco.com/download/home/282600534/type/280926587/release/8.5IRCM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;They said the TAC recommended releases &lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc9" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc9&lt;/A&gt; should get updated with that info soon (not yet I see).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you still have the problem with the other APs then try factory defaulting them (often fixes that type of problem) and if that doesn't help you'll need to get full console logs from at least one of them and ideally packet captures of the CAPWAP discovery/join at the same time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 11:55:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/certificate-unknown-alert/m-p/4316113#M227842</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2021-03-30T11:55:30Z</dc:date>
    </item>
  </channel>
</rss>

