<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP not joining Controller in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5102322#M271370</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/144936"&gt;@jeremiah.cox2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;SPAN&gt;Spent several hours on with TAC before we discovered this.&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Da fuq?&amp;nbsp; Several hours???&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are all volunteers in this forum.&amp;nbsp; None of us work for Cisco TAC but&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&amp;amp; &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319960"&gt;@jagan.chowdam&lt;/a&gt;&amp;nbsp;have provided the right answer/solution within 45 minutes after this thread went up.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 12 May 2024 00:54:10 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2024-05-12T00:54:10Z</dc:date>
    <item>
      <title>AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100485#M271314</link>
      <description>&lt;P&gt;I have a Cisco 3700 Series AP and trying to connect it to a WLC 5508. I have getting a certificate validation failed error, however when I use the command "show crypto pki certificates" no such expired certificate shows up. Previously had an issue with certificate on this AP, and I made it so that the WLC ignores expiry of certificates through the CLI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Mar 1 00:01:19.167: %CAPWAP-3-ERRORLOG: Go join a capwap controller&lt;BR /&gt;*May 10 14:52:36.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.27.10.5 peer_port: 5246&lt;BR /&gt;*May 10 14:52:38.235: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 1468F48300000002CF39) has expired. Validity period ended on 00:51:11 UTC Apr 26 2024Peer certificate verification failed 001A&lt;/P&gt;&lt;P&gt;*May 10 14:52:38.235: %CAPWAP-3-ERRORLOG: Certificate verification failed!&lt;BR /&gt;*May 10 14:52:38.235: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:467 Certificate verified failed!&lt;BR /&gt;*May 10 14:52:38.235: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 172.27.10.5:5246set_radio_pwr_mode: bad radio unit# 0&lt;BR /&gt;set_radio_pwr_mode: bad radio unit# 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 15:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100485#M271314</guid>
      <dc:creator>singh7881</dc:creator>
      <dc:date>2024-05-10T15:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100610#M271322</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI ::&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; What software version is the&lt;STRONG&gt; 5508&lt;/STRONG&gt; running ?&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 15:57:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100610#M271322</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-05-10T15:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100612#M271323</link>
      <description>&lt;P&gt;Please refer the Field Notice:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And follow the&amp;nbsp;Workaround/Solution mentioned.&lt;/P&gt;
&lt;P&gt;You have AirOS Controller 5508. Use command and look for&amp;nbsp;&lt;STRONG&gt;Cisco SHA1 device cert&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;entry&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;show certificate all&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;Jagan Chowdam&lt;/P&gt;
&lt;P&gt;/**Pls rate useful responses**/&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 16:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100612#M271323</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-05-10T16:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100614#M271325</link>
      <description>&lt;P&gt;I had success in temporarily rolling the system date back on the controller as the certificate on the AP was expired. Spent several hours on with TAC before we discovered this. NTP will adjust the date/time on next poll though so as soon as that AP loses connectivity it wont connect again. Ultimately we upgraded our APs and Controllers.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 16:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5100614#M271325</guid>
      <dc:creator>jeremiah.cox2</dc:creator>
      <dc:date>2024-05-10T16:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5102305#M271368</link>
      <description>&lt;P&gt;The solution for anyone else reading this is to upgrade the 5508 to 8.5.182.11 (link below) and read through all the field notices below carefully to make sure you've applied all the configuration required to deal with expired certs.&lt;/P&gt;
&lt;P&gt;This is a &lt;STRONG&gt;very&lt;/STRONG&gt; well known problem so it should have taken TAC about 2 minutes to diagnose this!&amp;nbsp; The fact that it took hours reflects on the quality of many first line TAC staff these days.&lt;/P&gt;
&lt;P&gt;Note that both WLC and AP certs can expire so even if AP cert has not expired, very old WLCs like 5508 may also have expired certs.&amp;nbsp; This is covered in the field notices.&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2024 12:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5102305#M271368</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-05-11T12:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5102322#M271370</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/144936"&gt;@jeremiah.cox2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;SPAN&gt;Spent several hours on with TAC before we discovered this.&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Da fuq?&amp;nbsp; Several hours???&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are all volunteers in this forum.&amp;nbsp; None of us work for Cisco TAC but&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&amp;amp; &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319960"&gt;@jagan.chowdam&lt;/a&gt;&amp;nbsp;have provided the right answer/solution within 45 minutes after this thread went up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 00:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5102322#M271370</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2024-05-12T00:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5102521#M271381</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;&amp;gt;..&lt;STRONG&gt;&lt;EM&gt;.The fact that &lt;U&gt;it took hours&lt;/U&gt; reflects on the quality of many first line TAC staff these days.&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; We are the best!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2024 16:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5102521#M271381</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-05-11T16:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103443#M271442</link>
      <description>&lt;P&gt;It is running version 8.0.140.0&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 10:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103443#M271442</guid>
      <dc:creator>singh7881</dc:creator>
      <dc:date>2024-05-13T10:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103448#M271445</link>
      <description>&lt;P&gt;8.0.140.0 will not work reliably without constant workarounds being applied.&amp;nbsp; You obviously have not read the field notices below - please do so without further delay?&lt;/P&gt;
&lt;P&gt;You need to update to 8.5.182.11 (link below) and apply the config for expired certs as per&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html" target="_blank" rel="nofollow noopener noreferrer"&gt;Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration&lt;/A&gt;&amp;nbsp; You will need to set the WLC time back to allow the AP to join and download new software and config.&amp;nbsp; After that you can re-enable NTP for correct system time.&lt;/P&gt;
&lt;P&gt;Before you update to 8.5.182.11 check the compatibility matrix (link below) to make sure all your AP models will still be supported on the new version.&lt;/P&gt;
&lt;P&gt;If you don't update the software you'll just be wasting time trying to resolve these issues.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 10:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103448#M271445</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-05-13T10:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103454#M271449</link>
      <description>&lt;P&gt;Hi Rich, thanks for this solution. I will try to apply it as soon as possible.&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319960"&gt;@jagan.chowdam&lt;/a&gt;&amp;nbsp;asked me to find the&amp;nbsp;&lt;STRONG&gt;Cisco SHA1 device cert&amp;nbsp;&lt;/STRONG&gt;certificate in the WLC and I can see that it expired on the date shown in the logs in my original post. One thing I am wondering though is why is that only 1 AP was affected? All our other APs are also Cisco 3700 Series. If a certificate in the WLC has expired shouldn't it affect all APs?&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 10:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103454#M271449</guid>
      <dc:creator>singh7881</dc:creator>
      <dc:date>2024-05-13T10:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: AP not joining Controller</title>
      <link>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103700#M271458</link>
      <description>&lt;P&gt;Some of the x700 APs had SHA1 certs and some had SHA2 certs depending on when they were manufactured and that means they behave differently when handling certificates.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 15:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-not-joining-controller/m-p/5103700#M271458</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-05-13T15:31:02Z</dc:date>
    </item>
  </channel>
</rss>

