<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reloading 9800-CL after certificate renewal in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4959308#M262938</link>
    <description>&lt;P&gt;Does the other SSID use a custom parameter map that might be using the old trustpoint?&lt;BR /&gt;Or maybe you're extra an external web auth like ISE or 3rd party service?&lt;BR /&gt;If you deleted the old certificate then how could the WLC still be using the old cert?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Nov 2023 17:23:00 GMT</pubDate>
    <dc:creator>Rich R</dc:creator>
    <dc:date>2023-11-14T17:23:00Z</dc:date>
    <item>
      <title>Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4954377#M262618</link>
      <description>&lt;P&gt;Hi, I have a pair of 9800-CL's in HA (17.9.3). A certificate expired recently for one of the SSID's which I've renewed and uploaded to the WLC. However the new certificate hasn't taken effect yet and it seems I need to reboot the WLC's for the new certificate to take over.&lt;/P&gt;
&lt;P&gt;How do I reload each WLC independently so we don't lose any service as the reload command looks like it reloads both WLC's?&lt;/P&gt;
&lt;P&gt;Many thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 16:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4954377#M262618</guid>
      <dc:creator>CDSFDSDXC</dc:creator>
      <dc:date>2023-11-06T16:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4954412#M262620</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;- CLI&lt;/STRONG&gt; command&amp;nbsp; &lt;FONT color="#008000"&gt;&lt;STRONG&gt;redundancy force-switchover&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp; , will reboot the current controller (command executed on only)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 17:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4954412#M262620</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-11-06T17:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4955008#M262674</link>
      <description>&lt;P&gt;There should not be any need to reload 9800-CL for certificate updates.&amp;nbsp; In fact a reload will not change the config so won't solve your problem.&amp;nbsp;&amp;nbsp;What type of certificate did you change and what procedure did you follow?&lt;/P&gt;
&lt;P&gt;Installing the certificate just creates a new PKI trustpoint.&amp;nbsp; After that you need to tell the service (eg web auth or web admin) to use the new trustpoint:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html#toc-hId--466302648" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html#toc-hId--466302648&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 15:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4955008#M262674</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-11-07T15:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4955016#M262675</link>
      <description>&lt;P&gt;Since its for SSID, I assuming its for local webauth, you just need to restart the http service and select the new trustpoint for webauth, see section local web authentication &lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html#toc-hId--466302648" target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 15:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4955016#M262675</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-11-07T15:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4956440#M262734</link>
      <description>&lt;P&gt;Yes it's for WebAuth. I've tried running the below commands as per the guide:&lt;/P&gt;
&lt;PRE&gt;9800(config)#&lt;STRONG&gt;no ip http server&lt;/STRONG&gt;&lt;BR /&gt;9800(config)#&lt;STRONG&gt;ip http server&lt;/STRONG&gt; &lt;/PRE&gt;
&lt;P&gt;But the expiry dates haven't updated when I do a &lt;EM&gt;show crypto pki certificates&lt;/EM&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;Could the issue be that both the old and new certificates have the same name and it's getting confused between the two? Do I need to remove the expired cert before adding the new one?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 14:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4956440#M262734</guid>
      <dc:creator>CDSFDSDXC</dc:creator>
      <dc:date>2023-11-09T14:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4956529#M262739</link>
      <description>&lt;P&gt;It's think it's impossible to have 2 trustpoints with the same name - are you &lt;STRONG&gt;sure&lt;/STRONG&gt; about that?&lt;BR /&gt;If you do have 2 with the same name then I guess it would be a good idea to delete the old one because it will probably just pick up the first one which may be the old one.&lt;BR /&gt;Did you configure the parameter map to use the new certificate trustpoint as per the guide?&lt;BR /&gt;You can delete the old cert/trustpoint after you've configured it to use the new one.&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;But the expiry dates haven't updated when I do a&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;show crypto pki certificates&lt;/EM&gt;" - that sounds like you haven't even uploaded the new certificate.&amp;nbsp; Whether you're using it or not it should still be there.&lt;BR /&gt;Really though you should be using "show crypto pki trustpoints" because it's the trustpoint that you configure on the parameter map, not the certificate.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;parameter-map type webauth global&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;type webauth&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;trustpoint &amp;lt;trustpoint-name&amp;gt;.p12&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 16:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4956529#M262739</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-11-09T16:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4959196#M262935</link>
      <description>&lt;P&gt;I've now updated the device certificate and I can see that it's in date. However there are two SSID's that use the certificate for Web Auth and only one has updated. When trying to log into these SSIDs from the users point of view one is still complaining about and expired certificate. The new certificate has been selected in Web Auth Global Parameter Map and the old certificate deleted from the Trustpoints list. Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 15:24:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4959196#M262935</guid>
      <dc:creator>CDSFDSDXC</dc:creator>
      <dc:date>2023-11-14T15:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4959249#M262936</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Have a checkup of the&amp;nbsp;&lt;SPAN&gt;9800-CL controller configuration with the CLI command &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt; &lt;/FONT&gt;; &lt;EM&gt;feed the output into :&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 16:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4959249#M262936</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-11-14T16:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4959308#M262938</link>
      <description>&lt;P&gt;Does the other SSID use a custom parameter map that might be using the old trustpoint?&lt;BR /&gt;Or maybe you're extra an external web auth like ISE or 3rd party service?&lt;BR /&gt;If you deleted the old certificate then how could the WLC still be using the old cert?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 17:23:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/4959308#M262938</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-11-14T17:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/5172485#M275305</link>
      <description>&lt;P&gt;Apologies for the late reply, but it was because I hadn't installed the certificate on the guest anchor WLC!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 14:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/5172485#M275305</guid>
      <dc:creator>CDSFDSDXC</dc:creator>
      <dc:date>2024-09-06T14:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Reloading 9800-CL after certificate renewal</title>
      <link>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/5172492#M275307</link>
      <description>&lt;P&gt;Wow... that took a while:), but it's great to see folks post the answer as that will help others when they are searching for answers.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 15:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/reloading-9800-cl-after-certificate-renewal/m-p/5172492#M275307</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2024-09-06T15:02:05Z</dc:date>
    </item>
  </channel>
</rss>

