<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I generate self signed 9800 WLC cert for web admin in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627028#M242986</link>
    <description>&lt;P&gt;Hello people,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone how can I generate a self signed certificate on my Cisco 9800 WLC for web admin?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using a 16.12.2s release and I can generate the RSA key pair with GUI or via CLI, but when I create the trustpoint and I set the rsa keypair plus the Subject name and other values it seems that the trustpoint it's empty:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My-9800-WLC# show crypto pki trustpoints&lt;BR /&gt;Trustpoint my-self-signed-cert:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The trustpoint it's configured like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My-9800-WLC(ca-trustpoint)#show&lt;BR /&gt;enrollment retry count 999&lt;BR /&gt;enrollment retry period 1&lt;BR /&gt;subject-name C=IT, ST=Italy, L=Milan, O=MyORG, OU=MyORG IT, CN=myorg.local&lt;BR /&gt;subject-alt-name myorg.local&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair self-signed-key-test&lt;BR /&gt;hash sha1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I generate a self-signed certificate via CLI or GUI?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2022 11:14:11 GMT</pubDate>
    <dc:creator>PythonUser777</dc:creator>
    <dc:date>2022-06-07T11:14:11Z</dc:date>
    <item>
      <title>How can I generate self signed 9800 WLC cert for web admin</title>
      <link>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627028#M242986</link>
      <description>&lt;P&gt;Hello people,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone how can I generate a self signed certificate on my Cisco 9800 WLC for web admin?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using a 16.12.2s release and I can generate the RSA key pair with GUI or via CLI, but when I create the trustpoint and I set the rsa keypair plus the Subject name and other values it seems that the trustpoint it's empty:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My-9800-WLC# show crypto pki trustpoints&lt;BR /&gt;Trustpoint my-self-signed-cert:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The trustpoint it's configured like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My-9800-WLC(ca-trustpoint)#show&lt;BR /&gt;enrollment retry count 999&lt;BR /&gt;enrollment retry period 1&lt;BR /&gt;subject-name C=IT, ST=Italy, L=Milan, O=MyORG, OU=MyORG IT, CN=myorg.local&lt;BR /&gt;subject-alt-name myorg.local&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair self-signed-key-test&lt;BR /&gt;hash sha1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I generate a self-signed certificate via CLI or GUI?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 11:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627028#M242986</guid>
      <dc:creator>PythonUser777</dc:creator>
      <dc:date>2022-06-07T11:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: How can I generate self signed 9800 WLC cert for web admin</title>
      <link>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627104#M242994</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Take a look here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title="https://www.niap-ccevs.org/MMO/Product/st_vid11044-agd.pdf" href="https://www.niap-ccevs.org/MMO/Product/st_vid11044-agd.pdf" target="_self"&gt;https://www.niap-ccevs.org/MMO/Product/st_vid11044-agd.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title="https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=2ahUKEwi62bDjr5v4AhV1upUCHU_WAKUQFnoECGMQAQ&amp;amp;url=https%3A%2F%2Fwww.niap-ccevs.org%2FMMO%2FProduct%2Fst_vid11044-agd.pdf&amp;amp;usg=AOvVaw0LJOVSQVZlNDVLulWyEKzs" href="https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=2ahUKEwi62bDjr5v4AhV1upUCHU_WAKUQFnoECGMQAQ&amp;amp;url=https%3A%2F%2Fwww.niap-ccevs.org%2FMMO%2FProduct%2Fst_vid11044-agd.pdf&amp;amp;usg=AOvVaw0LJOVSQVZlNDVLulWyEKzs" target="_self"&gt;https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=2ahUKEwi62bDjr5v4AhV1upUCHU_WAKUQFnoECGMQAQ&amp;amp;url=https%3A%2F%2Fwww.niap-ccevs.org%2FMMO%2FProduct%2Fst_vid11044-agd.pdf&amp;amp;usg=AOvVaw0LJOVSQVZlNDVLulWyEKzs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 12:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627104#M242994</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-06-07T12:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: How can I generate self signed 9800 WLC cert for web admin</title>
      <link>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627330#M243003</link>
      <description>&lt;P&gt;16.12.X code is bit old, suggest to upgrade to latest 17.3.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;follow below guide for certificate : ( same way you can sign local CA instead of 3rd party) - Hope that help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 16:30:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627330#M243003</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-07T16:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: How can I generate self signed 9800 WLC cert for web admin</title>
      <link>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627430#M243008</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;mentioned please upgrade your WLC to the latest Cisco TAC recommended code. You can find it here&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214749-tac-recommended-ios-xe-builds-for-wirele.html" target="_blank"&gt;Recommended Cisco IOS XE Releases for Catalyst 9800 Wireless LAN Controllers - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Basically it depends on the AP model's registered to your WLC, if you have any Wave1 AP's latest recommended code is 17.3.5a CCO image + SMU, if you have all WiFi6 AP's then you can upgrade to 17.6.3.&lt;/P&gt;
&lt;P&gt;If you have physical controller it is recommended that you upgrade the ROMMON to the latest recommended release as well.&lt;/P&gt;
&lt;P&gt;If you are looking for Self signed certificate for CAPWAP between AP to WLC then follow the below;&lt;/P&gt;
&lt;P class="pBulletCMT"&gt;&lt;SPAN&gt;●&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Delete the certificates which were copied along with the configuration. To do this, first check the existing certificates using the command “show crypto pki trustpoint”&lt;/P&gt;
&lt;P class="pBulletCMT"&gt;&lt;SPAN&gt;●&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Delete the existing certificate authority “WLC_CA”:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;no crypto pki server WLC_CA&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="pBulletCMT"&gt;&lt;SPAN&gt;●&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Delete existing device certificates:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;no crypto pki trustpoint "&amp;lt;hostname&amp;gt;_WLC_TP"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="pBulletCMT"&gt;&lt;SPAN&gt;●&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Create a new SSC for the management interface using the exec command:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;wireless config vwlc-ssc key-size 2048 signature-algo sha256 password 0 &amp;lt;password&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="pBulletCMT"&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#:~:text=register%20idtoken%20%3CTOKENID%3E-,There,-are%20extra%20considerations" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#:~:text=register%20idtoken%20%3CTOKENID%3E-,There,-are%20extra%20considerations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you need to install certificate in 9800 for any other purpose it is covered in the below article&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html" target="_blank"&gt;Generate and Download CSR Certificates on Catalyst 9800 WLCs - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 18:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-can-i-generate-self-signed-9800-wlc-cert-for-web-admin/m-p/4627430#M243008</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-06-07T18:58:54Z</dc:date>
    </item>
  </channel>
</rss>

