<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems uploading the whole certificate chain to cisco WLC in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4553600#M238512</link>
    <description>&lt;P&gt;So what did you do to make it work?&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 14:35:03 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2022-02-16T14:35:03Z</dc:date>
    <item>
      <title>Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551795#M238398</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to upload a certificate for web auth and I am having issues to see the whole chain when I prompt the show certificate webauth command. When I connect to the guest SSID I just see the device certificate and not the whole chain so the browser is not trusting the ssl certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that it could be related with the the untrust for the intermediate CA. Does anybody know if there is an option to upload the intermediate CA certificate?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The device is a mobility express in 8.2.x version. Any other idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for support!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 10:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551795#M238398</guid>
      <dc:creator>unaiabrisketa</dc:creator>
      <dc:date>2022-02-14T10:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551944#M238406</link>
      <description>&lt;P&gt;Did you bundle the pem file with the root, intermediate(s) and the device certificate?&amp;nbsp; If so, you should see the chain properly when viewing the certificate on a browser.&amp;nbsp; Take a look at this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_blank"&gt;Generate CSR for Third-Party Certificates and Download Chained Certificates to the WLC - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can search the web for "cisco mobility express wlc 3rd party certificate"&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551944#M238406</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-02-14T15:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551953#M238408</link>
      <description>&lt;P&gt;8.2 is end of life.&amp;nbsp; Even the end of life notice seems to have disappeared from Cisco web site!&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/wireless-controllers/bulletin-c25-738147.html#EarlyDeploymentEDreleases" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/wireless-controllers/bulletin-c25-738147.html#EarlyDeploymentEDreleases&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Although Google still has a cached copy at the moment:&amp;nbsp;&lt;A href="https://webcache.googleusercontent.com/search?q=cache:xO77LjSGw_sJ:https://www.cisco.com/c/en/us/products/collateral/wireless/8500-series-wireless-controllers/bulletin-c25-742074.pdf+&amp;amp;cd=3&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;gl=uk" target="_blank"&gt;https://webcache.googleusercontent.com/search?q=cache:xO77LjSGw_sJ:https://www.cisco.com/c/en/us/products/collateral/wireless/8500-series-wireless-controllers/bulletin-c25-742074.pdf+&amp;amp;cd=3&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;gl=uk&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So I'd start by making sure you're on up to date supported software for a start:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc12" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc12&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you go to 8.10 you might need to go via 8.5 as an intermediate - depends what other APs you're supporting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for your certificate issue:&lt;/P&gt;
&lt;P&gt;- I don't think loading the full cert chain will magically cause the browser to trust your cert - that really depends on the browser trusted root CAs, but entirely browser and OS dependent.&lt;/P&gt;
&lt;P&gt;- If you follow the instructions for uploading your cert then you should be uploading the PEM file for the complete cert chain already?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I don't see any instructions specific to ME so I wonder if it is even supported on ME?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551953#M238408</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-02-14T15:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551954#M238409</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have uploaded the whole chain in the same pem file with the private key, but I am not being able to see it when I saw the redirection of the cisco wireless controller. If I prompt the show certificate webauth command I don't see the whole chain, do you see a complete chain when you issue that command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could it be because of the lack of the intermediate certificate in the trust list of the Cisco WLC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Unai&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551954#M238409</guid>
      <dc:creator>unaiabrisketa</dc:creator>
      <dc:date>2022-02-14T15:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551959#M238411</link>
      <description>&lt;P&gt;The document doesn't state to upload the private key.&amp;nbsp; So that tells me that the pem file you created is incorrect and doesn't follow how the certificate should be bundled.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551959#M238411</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-02-14T15:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551974#M238416</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326193"&gt;@Scott Fella&lt;/a&gt;&amp;nbsp;step 4 of Step 2 option B&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html#anc13" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html#anc13&lt;/A&gt;&amp;nbsp;explains how to add the key in the final step before uploading the cert chain.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551974#M238416</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-02-14T15:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551983#M238419</link>
      <description>&lt;P&gt;"show certificate webauth" does not show the full chain for me on WLC running 8.0, 8.5 or 8.10&lt;/P&gt;
&lt;P&gt;And is working perfectly.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551983#M238419</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-02-14T15:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551986#M238420</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;I was making sure that the pem file when put together only has the certificates.&amp;nbsp; and should look like the following.&amp;nbsp; I have seen folks take a certificate chain and bundle it incorrectly.&amp;nbsp; That option B could be skipped if option A was done properly.&amp;nbsp; Only way to tell is if the cert was attached or if it looks like something below.&lt;/P&gt;
&lt;PRE&gt;------BEGIN CERTIFICATE------&lt;BR /&gt;*Device cert*&lt;BR /&gt;------END CERTIFICATE------&lt;BR /&gt;------BEGIN CERTIFICATE------&lt;BR /&gt;*Intermediate CA cert *&lt;BR /&gt;------END CERTIFICATE--------&lt;BR /&gt;------BEGIN CERTIFICATE------&lt;BR /&gt;*Root CA cert *&lt;BR /&gt;------END CERTIFICATE------&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4551986#M238420</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-02-14T15:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4552536#M238446</link>
      <description>&lt;P&gt;One small note. Depending on how you have joined the certificates, you sometimes have comments added between the lines&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;------END CERTIFICATE------
------BEGIN CERTIFICATE------&lt;/PRE&gt;
&lt;P&gt;To check this, open the certificate in notepad++ and remove all comments between those lines and save it. Same goes for such comments at the top or bottom of the certificate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 09:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4552536#M238446</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-02-15T09:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4552861#M238464</link>
      <description>&lt;P&gt;Is there any way to check if the full chain is correctly uploaded? Can I connect to the virtual IP of the web auth?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't find the way to do that...&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 16:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4552861#M238464</guid>
      <dc:creator>unaiabrisketa</dc:creator>
      <dc:date>2022-02-15T16:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4552862#M238465</link>
      <description>&lt;P&gt;Why not try it and see.&amp;nbsp; Firefox can show you the whole chain or else you have to view the certificate and see if the whole chain is there or not.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 16:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4552862#M238465</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-02-15T16:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4553366#M238482</link>
      <description>&lt;P&gt;Hi Scott,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have physical access to the AP, and logically, I don't have routes for the 192.0.2.1 IP address through my VPN connection. I have tried to upload it to the webadmin certificate, I have checked that the whole chain is uploaded, so it seems that it is now working correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Unai&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 09:12:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4553366#M238482</guid>
      <dc:creator>unaiabrisketa</dc:creator>
      <dc:date>2022-02-16T09:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4553497#M238496</link>
      <description>&lt;P&gt;Ah great. Otherwise if you have openssl around, you can use this command:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;openssl s_client -connect host.host:9999&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Simply adjust the hostname and port. You get either provided with just the server identity certificate or with the whole chain.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example for &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;&amp;nbsp;it looks like this:&lt;/P&gt;
&lt;PRE&gt;openssl s_client -connect www.cisco.com:443
CONNECTED(00000003)
depth=2 C = US, O = IdenTrust, CN = IdenTrust Commercial Root CA 1
verify return:1
depth=1 C = US, O = IdenTrust, OU = HydrantID Trusted Certificate Service, CN = HydrantID Server CA O1
verify return:1
depth=0 CN = www.cisco.com, O = Cisco Systems Inc., L = San Jose, ST = California, C = US
verify return:1
---
Certificate chain
 0 s:CN = www.cisco.com, O = Cisco Systems Inc., L = San Jose, ST = California, C = US
   i:C = US, O = IdenTrust, OU = HydrantID Trusted Certificate Service, CN = HydrantID Server CA O1
 1 s:C = US, O = IdenTrust, OU = HydrantID Trusted Certificate Service, CN = HydrantID Server CA O1
   i:C = US, O = IdenTrust, CN = IdenTrust Commercial Root CA 1
 2 s:C = US, O = IdenTrust, CN = IdenTrust Commercial Root CA 1
   i:C = US, O = IdenTrust, CN = IdenTrust Commercial Root CA 1
---&lt;/PRE&gt;
&lt;P&gt;If it's showing more than one certificate at the top (like here with the three certificates) you have received the probably complete chain. Here the depth 2 is the root, depth 1 is the optional intermediate and depth 0 is the server identity certificate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 12:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4553497#M238496</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2022-02-16T12:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problems uploading the whole certificate chain to cisco WLC</title>
      <link>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4553600#M238512</link>
      <description>&lt;P&gt;So what did you do to make it work?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 14:35:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-uploading-the-whole-certificate-chain-to-cisco-wlc/m-p/4553600#M238512</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-02-16T14:35:03Z</dc:date>
    </item>
  </channel>
</rss>

