<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AP 3702 certificate expiration date in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/4965378#M263380</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;How can I find out the certificate expiration date of an AP 3702? I have seen the 'show crypto pki certificates' command in various forums but in the case of my AP it does not recognize that command.&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
    <pubDate>Fri, 24 Nov 2023 06:08:17 GMT</pubDate>
    <dc:creator>Aleck_Sei</dc:creator>
    <dc:date>2023-11-24T06:08:17Z</dc:date>
    <item>
      <title>AP 3702 certificate expiration date</title>
      <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/4965378#M263380</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;How can I find out the certificate expiration date of an AP 3702? I have seen the 'show crypto pki certificates' command in various forums but in the case of my AP it does not recognize that command.&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 06:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/4965378#M263380</guid>
      <dc:creator>Aleck_Sei</dc:creator>
      <dc:date>2023-11-24T06:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: AP 3702 certificate expiration date</title>
      <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/4965399#M263382</link>
      <description>&lt;P&gt;Cisco used to provide a tool to check the certificate (&lt;A href="https://community.cisco.com/t5/wireless-mobility-knowledge-base/access-point-certificate-check-tool-apcertcheck/ta-p/3155582)" target="_blank"&gt;https://community.cisco.com/t5/wireless-mobility-knowledge-base/access-point-certificate-check-tool-apcertcheck/ta-p/3155582)&lt;/A&gt;&amp;nbsp;but this is now integrated on WLAN poller tool (&lt;A href="https://developer.cisco.com/docs/wireless-troubleshooting-tools/#!wireless-troubleshooting-tools/wireless-troubleshooting-tools" target="_blank"&gt;https://developer.cisco.com/docs/wireless-troubleshooting-tools/#!wireless-troubleshooting-tools/wireless-troubleshooting-tools&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 07:00:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/4965399#M263382</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2023-11-24T07:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: AP 3702 certificate expiration date</title>
      <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/4965753#M263410</link>
      <description>&lt;P&gt;Why waste time faffing around trying to check certificate dates?&lt;/P&gt;
&lt;P&gt;Just upgrade the software and use the workaround process provided in the field notice below (FN-63942) and then you don't have to worry about whether the certificates are expired or not.&lt;/P&gt;
&lt;P&gt;"sh crypto pki certificates" works fine on my 3702:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;3702#sh crypto pki certificates&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CA Certificate&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Status: Available&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Certificate Serial Number (hex): 01&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Certificate Usage: Signature&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Issuer:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=Cisco Root CA M2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;o=Cisco&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Subject:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=Cisco Root CA M2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;o=Cisco&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Validity Date:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;start date: 13:00:18 UTC Nov 12 2012&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;end date: 13:00:18 UTC Nov 12 2037&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Associated Trustpoints: Trustpool cisco-m2-root-cert&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Storage:&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 17:01:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/4965753#M263410</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-11-24T17:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: AP 3702 certificate expiration date</title>
      <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5056501#M269768</link>
      <description>&lt;P&gt;I have more and more old C3702i that stops working because of expired certifikates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I installed a virtual WLC9800 where I adjusted the date to some time in the past.&lt;/P&gt;&lt;P&gt;In there I have contact with the AP's.&lt;/P&gt;&lt;P&gt;But even when I upgrade the software to the newest version, it will not update the expiry date on the certificates&lt;/P&gt;&lt;P&gt;The software I have tried for the AP's are&amp;nbsp;Release 15.3.3-JPQ2, which is dated March 23, 2024&lt;/P&gt;&lt;P&gt;What can I do?&lt;/P&gt;&lt;P&gt;EDIT:&lt;BR /&gt;I don't get it. If I go to the virtual WLC, and to Edit AP -&amp;gt; Inventory, it says:&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Certificate Expiry-time:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;03/13/2024 02:59:35&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;But when I SSH into the AP, and writes&amp;nbsp;show crypto pki certificates, it shows several certificates, whom many of them has expiry date long into the future.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;This one for example:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;CA Certificate&lt;BR /&gt;Status: Available&lt;BR /&gt;Certificate Serial Number (hex): 01&lt;BR /&gt;Certificate Usage: Signature&lt;BR /&gt;Issuer:&lt;BR /&gt;cn=Cisco Root CA M2&lt;BR /&gt;o=Cisco&lt;BR /&gt;Subject:&lt;BR /&gt;cn=Cisco Root CA M2&lt;BR /&gt;o=Cisco&lt;BR /&gt;Validity Date:&lt;BR /&gt;start date: 13:00:18 UTC Nov 12 2012&lt;BR /&gt;end date: 13:00:18 UTC Nov 12 2037&lt;BR /&gt;Associated Trustpoints: Trustpool cisco-m2-root-cert&lt;BR /&gt;Storage: &lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;But clearly it's the one showed under Edit AP -&amp;gt; Inventory that is getting used, since the AP will not associate with our production WLC&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 14:40:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5056501#M269768</guid>
      <dc:creator>dal</dc:creator>
      <dc:date>2024-04-04T14:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: AP 3702 certificate expiration date</title>
      <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5056509#M269770</link>
      <description>&lt;P&gt;The one that matters is the MIC - Manufacturing Installed Certificate.&amp;nbsp; It's installed in the AP in the factory and normally expires after 10 years.&amp;nbsp; It &lt;STRONG&gt;cannot&lt;/STRONG&gt; be updated or replaced.&lt;/P&gt;
&lt;P&gt;The only workaround is to force the WLC to ignore the expiry date of the AP MIC certificate using the config workaround provided in&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html &lt;/A&gt;&lt;BR /&gt;You would need to do that on &lt;STRONG&gt;both&lt;/STRONG&gt; the main 9800 and your virtual WLC so that the AP picks up and keeps the updated config on both.&amp;nbsp; Upgrading the software will not make any difference to the MIC on the AP.&lt;BR /&gt;Have you done that?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 14:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5056509#M269770</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-04-04T14:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: AP 3702 certificate expiration date</title>
      <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5056521#M269771</link>
      <description>&lt;P&gt;Thanks, I have entered the commands:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;configure terminal
crypto pki certificate map map1 1
&amp;nbsp;issuer-name co cisco manufacturing ca
crypto pki certificate map map1 2
&amp;nbsp;issuer-name co act2 sudi ca

crypto pki trustpool policy
&amp;nbsp;match certificate map1 allow expired-certificate
    
exit&lt;/PRE&gt;&lt;P&gt;Create a Certificate Map and Add the Rules&lt;/P&gt;&lt;PRE&gt;configure terminal&lt;BR /&gt;
crypto pki certificate map map1 1
issuer-name co Cisco Manufacturing CA&lt;/PRE&gt;&lt;P&gt;Use the Certificate Map Under the Trustpool Policy&lt;/P&gt;&lt;PRE&gt;configure terminal
crypto pki trustpool policy
match certificate map1 allow expired-certificate&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Guess we will have to wait and see the outcome.&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 15:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5056521#M269771</guid>
      <dc:creator>dal</dc:creator>
      <dc:date>2024-04-04T15:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: AP 3702 certificate expiration date</title>
      <link>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5160493#M274528</link>
      <description>&lt;P&gt;Hello everyone , So&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/290228"&gt;@dal&lt;/a&gt;&amp;nbsp;did this actually works? I 'm facing the same issue.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 19:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-3702-certificate-expiration-date/m-p/5160493#M274528</guid>
      <dc:creator>KarmaChris</dc:creator>
      <dc:date>2024-08-13T19:26:13Z</dc:date>
    </item>
  </channel>
</rss>

