<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP certificate validation error between 2 9800 WLCs cluster in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736321#M249361</link>
    <description>Ok that's a good point, I will try to set same mobility group name next&lt;BR /&gt;week and let you know if it's improving anything.&lt;BR /&gt;&lt;BR /&gt;Thanks !&lt;BR /&gt;</description>
    <pubDate>Sat, 10 Dec 2022 17:37:41 GMT</pubDate>
    <dc:creator>Clem58</dc:creator>
    <dc:date>2022-12-10T17:37:41Z</dc:date>
    <item>
      <title>AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4735815#M249342</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm testing 2 WLCs clusters, same versions 17.3.6. WLC01 and WLC02&lt;/P&gt;&lt;P&gt;I have 2 APs, one 3801I and one 3702E, when I move the APs from WLC01 to WLC02, using primary and secondary in High Availibility parameters, it's working perfectly.&lt;/P&gt;&lt;P&gt;But when I do the return, WLC02 to WLC01, the both APs cannot join, in the log we see :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSC_CERT_AUTH_FAILED: Failed to authorize controller, &lt;EM&gt;SSC certificate validation failed.Peer&lt;/EM&gt; certificate verification failed &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The only way to have them joining back WLC01 is to clear capwap private-config on 3702 and reset the 3802 with mode button.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As we want to have N+1 WLCs cluster (remote) at the final state, in production, I don't want to have to manually reset all the APs when they will failover back to the initial WLCs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is it anything you already faced ?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 16:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4735815#M249342</guid>
      <dc:creator>Clem58</dc:creator>
      <dc:date>2022-12-09T16:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4735839#M249344</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Could you run the configuration of&amp;nbsp; &lt;STRONG&gt;both&lt;/STRONG&gt; controllers through WirlessAnalyzer with the procedure mentioned below, look for differences in advisories (or configuration) which may be indicative :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;&amp;nbsp; &amp;nbsp;Use&amp;nbsp;the CLI command :&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;show&amp;nbsp; tech&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;U&gt;&amp;nbsp;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;, have the output analyzed by&amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/tools/WirelessAnalyzer/" target="_blank" rel="noopener nofollow noreferrer" data-saferedirecturl="https://www.google.com/url?q=https://cway.cisco.com/tools/WirelessAnalyzer/&amp;amp;source=gmail&amp;amp;ust=1662270212514000&amp;amp;usg=AOvVaw1v8X824xUFwNwiDM_o5Fxf"&gt;https://cway.cisco.com/&lt;WBR /&gt;tools/WirelessAnalyzer/&lt;/A&gt;&amp;nbsp; , please note do not use classical&lt;FONT color="#FF0000"&gt;&amp;nbsp;show tech-support&lt;/FONT&gt;&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;(short version) , use the command denoted &lt;FONT color="#008000"&gt;in green&lt;/FONT&gt; for Wireless Analyzer.&lt;/EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 17:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4735839#M249344</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-12-09T17:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4735846#M249345</link>
      <description>&lt;P&gt;&lt;SPAN class="font sty__i2fpl8__cls"&gt;&lt;SPAN class="size sty__xbw0j8__cls"&gt;&amp;nbsp;can you post the output &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="font sty__i2fpl8__cls"&gt;&lt;SPAN class="size sty__xbw0j8__cls"&gt;&amp;gt;show certificate ssc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="font sty__i2fpl8__cls"&gt;&lt;SPAN class="size sty__xbw0j8__cls"&gt;i think there is a bug on this i dont have in hand but will post later when i get chance.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 17:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4735846#M249345</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-12-09T17:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736011#M249351</link>
      <description>&lt;P&gt;The 3702 has a tiny flash space and can only accommodate one CAPWAP image.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To go from AireOS to IOS-XE (and back) means the AP will need to download the IOS every time it crosses over.&lt;/P&gt;
&lt;P&gt;Finally, the 2702/3702 are affected by&amp;nbsp;&lt;A class="_3t5uN8xUmg0TOwRCOGQEcU" style="font-family: inherit; background-color: #ffffff;" href="https://www.cisco.com/c/en/us/support/docs/field-notices/725/fn72524.html" target="_blank" rel="noopener nofollow ugc"&gt;FN - 72524 - During Software Upgrade/Downgrade, Cisco IOS APs Might Remain in Downloading State After December 4, 2022 Due to Certificate Expiration&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 23:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736011#M249351</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2022-12-09T23:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736217#M249357</link>
      <description>&lt;P&gt;What model of 9800 are you using - 9800-CL?&lt;/P&gt;
&lt;P&gt;This sounds suspiciously similar to a well known problem with vWLC on AireOS!&lt;BR /&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCva69352" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCva69352&lt;/A&gt;&lt;BR /&gt;You can try the&amp;nbsp;"&lt;SPAN&gt;Alternative workaround"&lt;/SPAN&gt; from that? (if it's even possible on 9800)&lt;BR /&gt;Either way I think you'll need to open a TAC case for it because I don't see any bugs open for it on 9800.&lt;BR /&gt;Presume you have configured (and verified) mobility between the WLCs with the hash configured as per&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_vewlc_mobility.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_vewlc_mobility.html&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 17:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736217#M249357</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-12-10T17:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736250#M249359</link>
      <description>&lt;P&gt;&lt;STRONG&gt;For Balaji&lt;BR /&gt;&lt;/STRONG&gt;"show certificate ssc" does not exist&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For Leo&lt;BR /&gt;&lt;/STRONG&gt;It's not the recent bug with 3702, as we have the same issue with 3802 AP.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For Rich&lt;BR /&gt;&lt;/STRONG&gt;There are different mobility groups, as the 2 clusters are in different sites (remote) so we don't have same mobility group, we don't need the 2 WLCs to share any RF data and so on. Anyway the migration from WLC01 to WLC02 is working, but not the inverse.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 15:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736250#M249359</guid>
      <dc:creator>Clem58</dc:creator>
      <dc:date>2022-12-10T15:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736319#M249360</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/451109"&gt;@Clem58&lt;/a&gt;&amp;nbsp;- yes I understand that but I think it may still fix this problem for you - it might actually be necessary to have this working as you intend.&amp;nbsp; So TRY IT and see if it helps?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 17:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736319#M249360</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-12-10T17:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736321#M249361</link>
      <description>Ok that's a good point, I will try to set same mobility group name next&lt;BR /&gt;week and let you know if it's improving anything.&lt;BR /&gt;&lt;BR /&gt;Thanks !&lt;BR /&gt;</description>
      <pubDate>Sat, 10 Dec 2022 17:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736321#M249361</guid>
      <dc:creator>Clem58</dc:creator>
      <dc:date>2022-12-10T17:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736324#M249362</link>
      <description>&lt;P&gt;It's not just setting the mobility group name.&lt;/P&gt;
&lt;P&gt;You need the working mobility connection between the WLCs so that they share hashes with each other and the APs store both WLC's hashes.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 17:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736324#M249362</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-12-10T17:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736407#M249363</link>
      <description>Yes of course I will add the peer WLCs into the mobility group.&lt;BR /&gt;</description>
      <pubDate>Sun, 11 Dec 2022 08:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4736407#M249363</guid>
      <dc:creator>Clem58</dc:creator>
      <dc:date>2022-12-11T08:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4737137#M249395</link>
      <description>&lt;P&gt;So my problem is solved, actually even with mobility enabled and peers added and UP, I still had this issue with SSC certificate validation.&lt;/P&gt;&lt;P&gt;After double checked the configs, I noticed a setting I left, on both WLCs, when I was tshooting the issue with 3702 AP (recent bug with certificate expiration), so I had added : &lt;SPAN&gt;wireless management certificate ssc auth-token 0 password&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After removing this settings, the APs can migrate from a WLC to another without any issue !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 14:39:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4737137#M249395</guid>
      <dc:creator>Clem58</dc:creator>
      <dc:date>2022-12-12T14:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: AP certificate validation error between 2 9800 WLCs cluster</title>
      <link>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4737203#M249407</link>
      <description>&lt;P&gt;Ah well glad you worked it out!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 16:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-certificate-validation-error-between-2-9800-wlcs-cluster/m-p/4737203#M249407</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-12-12T16:12:51Z</dc:date>
    </item>
  </channel>
</rss>

