<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C9800 WLC PKI Cert Renew Error in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111015#M271755</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/439615"&gt;@jaheshkhan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I needed to&amp;nbsp;&lt;SPAN&gt;select WLC from Inventory page in DNAC and update telemetry settings using force config push option. Seems this issue occurs after DNAC update&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2024 12:56:00 GMT</pubDate>
    <dc:creator>sroic</dc:creator>
    <dc:date>2024-05-20T12:56:00Z</dc:date>
    <item>
      <title>C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/4926267#M260822</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We have been receiving this error on our C9800-CL controller for some time now and not sure what it requires.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;%PKI-2-CERT_RENEW_FAIL: Certificate renewal failed for trustpoint sdn-network-infra-iwan Reason : Failed to get ID certificate from CA server&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Does anyone know what this might be related to. Currently our infrastructure and controller does not have any issues and this controller is managed by DNA Center.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sajid&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 22:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/4926267#M260822</guid>
      <dc:creator>sajidabbas</dc:creator>
      <dc:date>2023-09-19T22:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/4926376#M260831</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Note sure if the feature is supported on 9800 controller ; in that context start with a checkup of the controller configuration with the CLI command &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp; ; feed the output into :&amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;https://cway.cisco.com/wireless-config-analyzer/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;U&gt; &amp;nbsp;Some of these commands may provide insights :&lt;/U&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;show crypto pki certificates&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;show crypto pki timers&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;show crypto pki server&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;In the running-config , you can also enable : &lt;STRONG&gt;debug pki transaction&amp;nbsp;&lt;/STRONG&gt; and check logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Also check current software version ; compare too :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214749-tac-recommended-ios-xe-builds-for-wirele.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214749-tac-recommended-ios-xe-builds-for-wirele.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 06:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/4926376#M260831</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-09-20T06:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/4930447#M261071</link>
      <description>&lt;P&gt;Same issue but our 9800-L is not managed by DNA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 16:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/4930447#M261071</guid>
      <dc:creator>lrob5</dc:creator>
      <dc:date>2023-09-27T16:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5104836#M271552</link>
      <description>&lt;P&gt;Just got the same alert on same setup, did you find the solution maybe?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 09:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5104836#M271552</guid>
      <dc:creator>sroic</dc:creator>
      <dc:date>2024-05-15T09:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5104979#M271558</link>
      <description>&lt;P&gt;What is the DNA Center / Catalyst Center version?&lt;/P&gt;
&lt;P&gt;Can you run the following command on WLC:&lt;/P&gt;
&lt;PRE&gt;show telemetry internal connection&lt;/PRE&gt;
&lt;P&gt;I see couple of bugs listed with exact same issue:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvy30606?rfs=qvred" target="_self"&gt;&lt;SPAN&gt;CSCvy30606&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvu25442?rfs=qvred" target="_self"&gt;CSCvu25442&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Jagan Chowdam&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;/**Pls rate useful responses**/&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 13:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5104979#M271558</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-05-15T13:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5105029#M271561</link>
      <description>&lt;P&gt;DNA version is&lt;SPAN&gt;&amp;nbsp;2.3.5.5-70026, WLC is 17.9.4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This command doesnt exists at my WLC&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;show telemetry internal connection&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I did run&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;show telemetry connection all&lt;/PRE&gt;&lt;P&gt;found an Index name and with:&lt;/P&gt;&lt;PRE&gt;show telemetry internal connection 1795 detail&lt;/PRE&gt;&lt;P&gt;I got this:&lt;/P&gt;&lt;P&gt;Telemetry protocol manager stats:&lt;/P&gt;&lt;P&gt;Con str : &amp;lt;DNA IP&amp;gt;:25103:0:&amp;lt;WLC IP&amp;gt;&lt;BR /&gt;Sockfd : 114&lt;BR /&gt;Protocol : tls-native&lt;BR /&gt;State : CNDP_STATE_CONNECTED&lt;BR /&gt;Table id : 0&lt;BR /&gt;Profile : sdn-network-infra-iwan&lt;BR /&gt;Version : TLSv1.2&lt;BR /&gt;Wait Mask :&lt;BR /&gt;Connection Retries : 0&lt;BR /&gt;Send Retries : 28&lt;BR /&gt;Pending events : 0&lt;BR /&gt;Session requests : 1&lt;BR /&gt;Session replies : 1&lt;BR /&gt;Source ip : &amp;lt;WLC IP&amp;gt;&lt;BR /&gt;Bytes Sent : 127922718617&lt;BR /&gt;Msgs Sent : 30681689&lt;BR /&gt;Msgs Received : 0&lt;BR /&gt;Creation time: : Tue May 7 21:31:49:64&lt;BR /&gt;Last connected time: : Tue May 7 21:31:49:251&lt;BR /&gt;Last disconnect time: :&lt;BR /&gt;Last error: :&lt;BR /&gt;Connection flaps: : 0&lt;BR /&gt;Last flap Reason: :&lt;BR /&gt;Keep Alive Timeouts: : 0&lt;BR /&gt;Last Transport Error : No Error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 14:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5105029#M271561</guid>
      <dc:creator>sroic</dc:creator>
      <dc:date>2024-05-15T14:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5105133#M271568</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The state is CNDP_STATE_CONNECTED, indicating that the connection was successfully established.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check the status with the following commands&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;show crypto pki certificates verbose sdn-network-infra-iwan&lt;/CODE&gt;&lt;/PRE&gt;
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;show crypto pki trustpoint sdn-network-infra-iwan status&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 16:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5105133#M271568</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-05-15T16:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5105755#M271589</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319960"&gt;@jagan.chowdam&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;this is my output of those commands, not sure what to think of it:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;wlc-a#show crypto pki certificates verbose sdn-network-infra-iwan
Certificate
  Status: Available
  Version: 3
  Certificate Serial Number (hex): 56F2F3AD75229045
  Certificate Usage: General Purpose
  Issuer: 
    cn=sdn-network-infra-ca
  Subject:
    Name: wlc-a.eu-central-1.compute.internal
    cn=C9800-CL-K9_9B1KVTSUSVQ_sdn-network-infra-iwan
    hostname=wlc-a.eu-central-1.compute.internal
  Validity Date: 
    start date: 10:24:16 UTC Jul 26 2023
    end   date: 10:24:16 UTC Jul 25 2024
    renew date: 10:25:08 UTC May 16 2024
  Subject Key Info:
    Public Key Algorithm: rsaEncryption
    RSA Public Key: (2048 bit)
  Signature Algorithm: SHA512 with RSA Encryption
  Fingerprint MD5: EEBAE572 56F4D25C 0C73F2CB 7173D8A2 
  Fingerprint SHA1: 8594A177 49F0A75A 91727A16 3A811CB4 76C728E7 
  X509v3 extensions:
    X509v3 Key Usage: E0000000
      Digital Signature
      Non Repudiation
      Key Encipherment
    X509v3 Subject Key ID: 85A02533 93720D11 A90E2DF2 6318C367 AEC0C990 
    X509v3 Basic Constraints:
        CA: FALSE
    X509v3 Authority Key ID: 88123ACC 7E0D37EB 38270C55 E1D3FD60 865322DF 
    Authority Info Access:
    Extended Key Usage:
        Email Protection
        Client Auth
  Cert install time: 14:38:23 UTC Nov 19 2023 
  Associated Trustpoints: sdn-network-infra-iwan 
  Storage: nvram:sdn-network-#9045.cer
  Key Label: sdn-network-infra-iwan
  Key storage device: private config

CA Certificate
  Status: Available
  Version: 3
  Certificate Serial Number (hex): 2B736CDA315062D2
  Certificate Usage: Signature
  Issuer: 
    cn=sdn-network-infra-ca
  Subject: 
    cn=sdn-network-infra-ca
  Validity Date: 
    start date: 13:33:20 UTC Jun 8 2022
    end   date: 13:33:20 UTC Jun 8 2037
  Subject Key Info:
    Public Key Algorithm: rsaEncryption
    RSA Public Key: (2048 bit)
  Signature Algorithm: SHA512 with RSA Encryption
  Fingerprint MD5: 30955623 ACFA56E3 725AE71A 01643551 
  Fingerprint SHA1: DC7569CF 2070926E 7293898D 0236AF85 B9161AEB 
  X509v3 extensions:
    X509v3 Key Usage: 86000000
      Digital Signature
      Key Cert Sign
      CRL Signature
    X509v3 Subject Key ID: 88123ACC 7E0D37EB 38270C55 E1D3FD60 865322DF 
    X509v3 Basic Constraints:
        CA: TRUE
    X509v3 Authority Key ID: 88123ACC 7E0D37EB 38270C55 E1D3FD60 865322DF 
    Authority Info Access:
  Cert install time: 14:38:23 UTC Nov 19 2023 
  Associated Trustpoints: sdn-network-infra-iwan 
  Storage: nvram:sdn-network-#62D2CA.cer


wlc-a#show crypto pki trustpoint sdn-network-infra-iwan status
Trustpoint sdn-network-infra-iwan:
  Issuing CA certificate configured:
    Subject Name:
     cn=sdn-network-infra-ca
    Fingerprint MD5: 30955623 ACFA56E3 725AE71A 01643551 
    Fingerprint SHA1: DC7569CF 2070926E 7293898D 0236AF85 B9161AEB 
  Router General Purpose certificate configured:
    Subject Name:
     cn=C9800-CL-K9_9B1KVTSUSVQ_sdn-network-infra-iwan,hostname=wlc-a.eu-central-1.compute.internal
    Fingerprint MD5: EEBAE572 56F4D25C 0C73F2CB 7173D8A2 
    Fingerprint SHA1: 8594A177 49F0A75A 91727A16 3A811CB4 76C728E7 
  Last enrollment status: Failed
  Next enrollment attempt:
    10:25:08 UTC May 16 2024 
    * A new key will be generated *
    * Configuration will not be saved after enrollment *
  State:
    Keys generated ............. Yes (General Purpose, non-exportable)
    Issuing CA authenticated ....... Yes
    Certificate request(s) ..... Yes
&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Any ideas are welcome&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 09:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5105755#M271589</guid>
      <dc:creator>sroic</dc:creator>
      <dc:date>2024-05-16T09:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111011#M271753</link>
      <description>&lt;P&gt;Did your issue solved ? i faced the same problem now? can you provide the remediation if the issue got solved?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 12:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111011#M271753</guid>
      <dc:creator>jaheshkhan</dc:creator>
      <dc:date>2024-05-20T12:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111015#M271755</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/439615"&gt;@jaheshkhan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I needed to&amp;nbsp;&lt;SPAN&gt;select WLC from Inventory page in DNAC and update telemetry settings using force config push option. Seems this issue occurs after DNAC update&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 12:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111015#M271755</guid>
      <dc:creator>sroic</dc:creator>
      <dc:date>2024-05-20T12:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111164#M271761</link>
      <description>&lt;P&gt;in my case status is active and connection is up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but last fingerprint is showing as failed. similarly like you. so can i try your steps then?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 14:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111164#M271761</guid>
      <dc:creator>jaheshkhan</dc:creator>
      <dc:date>2024-05-20T14:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111174#M271762</link>
      <description>&lt;P&gt;Sounds pretty similar to outputs that I pasted above. I don't work at TAC but I believe you can &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 14:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5111174#M271762</guid>
      <dc:creator>sroic</dc:creator>
      <dc:date>2024-05-20T14:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5148893#M273675</link>
      <description>&lt;P&gt;I am facing the same issues. Is the solution you found interfering the Wifi-Experience of the User or can this be done "hitless"?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 09:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5148893#M273675</guid>
      <dc:creator>tpense</dc:creator>
      <dc:date>2024-07-23T09:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5148926#M273678</link>
      <description>&lt;P&gt;For me it wasn't interfering with anything on the wifi side&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 10:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5148926#M273678</guid>
      <dc:creator>sroic</dc:creator>
      <dc:date>2024-07-23T10:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5228604#M278127</link>
      <description>&lt;P&gt;This worked for me as well (On Cat 9300 switches), in inventory &amp;gt; actions &amp;gt; telemetry &amp;gt; update telemetry settings, need to select force push config and it renewed the expired cert for me as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some reason this isn't documented anywhere I could find, unless my google-fu is getting worse&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 18:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5228604#M278127</guid>
      <dc:creator>krsmith</dc:creator>
      <dc:date>2024-11-25T18:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5243085#M279457</link>
      <description>&lt;P&gt;The sdn-network-infra-iwan certificate and associated trust point is a Cisco Catalyst Center (formerly known as Cisco DNA Center) pushed certificate as part of establishing the telemetry connection with the applicable device. When we see the below error, this means that renewal of the client cert fails due to the inability to retrieve and identity cert from the CA.&lt;/P&gt;
&lt;P&gt;%PKI-2-CERT_RENEW_FAIL: Certificate renewal failed for trustpoint sdn-network-infra-iwan Reason : Failed to get ID certificate from CA server&lt;/P&gt;
&lt;P&gt;The CA in this instance is either Catalyst Center or a configured external SCEP broker which can be verified under the Menu &amp;gt; System &amp;gt; Settings &amp;gt; Certificate Authority (as seen in 2.3.7.x versions). Often, the cause for the renewal failure is due to a connectivity issue with the enrollment URL reachability. To find evidence of this, first verify the enrollment URL in the sdn-network-infra-iwan trustpoint:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px" data-unlink="true"&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;crypto pki trustpoint sdn-network-infra-iwan&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;enrollment url http://&amp;lt;your_FQDN/IP&amp;gt;:80/ejbca/publicweb/apply/scep/sdnscep&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Then, in the logs, you might be able to find a connectivity issue to the shared FQDN within that URL. For example:&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;FONT face="courier new,courier"&gt;%PKI-3-HOSTNAME_RESOLVE_ERR: Failed to resolve HOSTNAME/IPADDRESS :&amp;lt;your_FQDN/IP&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;The earlier shared debugging commands ran during an auto-enrollment should give you more details if this is not the cause of the certificate renewal failure. There are many other possible causes of auto-renewal failure on either the client or server side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 14:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5243085#M279457</guid>
      <dc:creator>niwirtz</dc:creator>
      <dc:date>2025-01-03T14:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5266726#M281298</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;we just had this problem that after DNA reboot we lost telemetry on our devices. Turned out that DNA wanted to refresh certs on the devices but was failing because it could not call enrollment url&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;%PKI-3-PKCS12_IMPORT_FAILURE: PKCS #12 import failed for trustpoint: sdn-network-infra-iwan. Reason: Failed to read PKCS12 from url: https://10.1.2.3/api/v1/trust-point/pkcs12/xxxyyyzzz&lt;/LI-CODE&gt;&lt;P&gt;So you can see that it uses IP address and not FQDN name of our DNA appliance (and we have system certificate with FQDN imported).&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what TAC suggested was to generate system certificate again but this time add this IP address to SAN field, so there are both FQDN and IP entries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I uploaded new system cert, DNA was able to refresh certs on devices and telemetry is working again. I hope this helps someone.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 11:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5266726#M281298</guid>
      <dc:creator>derobert87</dc:creator>
      <dc:date>2025-03-03T11:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5321593#M285583</link>
      <description>&lt;P&gt;1. Manually remove the “sdn-network-infra-iwan” certs from the WLC and save the configuration:&lt;BR /&gt;config t&lt;BR /&gt;no crypto pki trustpoint sdn-network-infra-iwan&lt;BR /&gt;end&lt;BR /&gt;wr&lt;BR /&gt;2. Re-sync the device from DNAC inventory:&lt;BR /&gt;a. Inventory &amp;gt; Select the WLC &amp;gt; Actions &amp;gt; Inventory &amp;gt; Resync Device&lt;BR /&gt;3. Once completed, do a force configuration push from DNAC:&lt;BR /&gt;a. From the inventory, select the WLC once &amp;gt; Actions &amp;gt; Telemetry &amp;gt; Update Telemetry Settings &amp;gt; Ensure "Force Configuration Push" is selected and click Next until completed.&lt;/P&gt;
&lt;P&gt;you will get this certificate again from dnc after synic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 12:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5321593#M285583</guid>
      <dc:creator>Chandan Singh</dc:creator>
      <dc:date>2025-08-18T12:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5321826#M285602</link>
      <description>&lt;P&gt;I am also facing the same issue on the 9800 WLC, and I resolved it with the steps below.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Manually remove the “sdn-network-infra-iwan” certs from the WLC and save the configuration:&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;config t&lt;/P&gt;
&lt;P&gt;no crypto pki trustpoint sdn-network-infra-iwan&lt;/P&gt;
&lt;P&gt;end&lt;/P&gt;
&lt;P&gt;wr&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Re-sync the device from DNAC inventory:&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Inventory &amp;gt; Select the WLC &amp;gt; Actions &amp;gt; Inventory &amp;gt; Resync Device&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Once completed, do a force configuration push from DNAC:&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;From the inventory, select the WLC once &amp;gt; Actions &amp;gt; Telemetry &amp;gt; Update Telemetry Settings &amp;gt; Ensure "Force Configuration Push" is selected and click Next until completed.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 19 Aug 2025 03:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5321826#M285602</guid>
      <dc:creator>Chandan Singh</dc:creator>
      <dc:date>2025-08-19T03:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 WLC PKI Cert Renew Error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5331672#M286458</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Did this require a reboot?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2025 07:35:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-wlc-pki-cert-renew-error/m-p/5331672#M286458</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2025-09-19T07:35:52Z</dc:date>
    </item>
  </channel>
</rss>

