<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132684#M272788</link>
    <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt; !! Got the link to the documentation&lt;/P&gt;&lt;P&gt;The PSK was less than 15 characters &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So probably this is the origin of the issue.&lt;/P&gt;&lt;P&gt;I will reset the AP now. You can consider this ticket solved and closed.&lt;/P&gt;&lt;P&gt;Again thanks for your support.&lt;/P&gt;&lt;P&gt;Joel&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2024 15:21:48 GMT</pubDate>
    <dc:creator>jguittet</dc:creator>
    <dc:date>2024-06-17T15:21:48Z</dc:date>
    <item>
      <title>CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5129510#M272671</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I face this issue that is indicated as not reproductible.&lt;/P&gt;&lt;P&gt;What can I do to help ?&lt;/P&gt;&lt;P&gt;Joel&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 10:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5129510#M272671</guid>
      <dc:creator>jguittet</dc:creator>
      <dc:date>2024-06-13T10:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5130569#M272672</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; - Ref :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx84736" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx84736&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;SPAN&gt;&lt;FONT color="#FF6600"&gt; None at the moment. &lt;/FONT&gt;To rejoin APs FIPS needs to be &lt;U&gt;&lt;STRONG&gt;disabled&lt;/STRONG&gt; &lt;/U&gt;on controller side.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 11:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5130569#M272672</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-14T11:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132298#M272740</link>
      <description>&lt;P&gt;What version of software are you running?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 00:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132298#M272740</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-17T00:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132407#M272763</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;this is not acceptable solution, I need FIPS to be enabled!&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;software version is 17.03.08a.&lt;/P&gt;&lt;P&gt;Thanks for the help on this.&lt;/P&gt;&lt;P&gt;Joel&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 07:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132407#M272763</guid>
      <dc:creator>jguittet</dc:creator>
      <dc:date>2024-06-17T07:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132410#M272764</link>
      <description>&lt;P&gt;Note: I can provide logs or anything else so that I can maybe help on solving this issue&amp;nbsp;CSCvx84736&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 07:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132410#M272764</guid>
      <dc:creator>jguittet</dc:creator>
      <dc:date>2024-06-17T07:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132449#M272766</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;.. .&lt;/EM&gt;&lt;EM&gt;I need FIPS to be enabled!&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;...&amp;nbsp;I can provide logs or anything&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; - The bug&amp;nbsp; (&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx84736" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx84736&lt;/A&gt;&amp;nbsp;) report is rather clear :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;...&lt;STRONG&gt;Workaround: &lt;FONT color="#FF0000"&gt;None at the moment.&lt;/FONT&gt; &lt;/STRONG&gt;To rejoin APs FIPS needs to be&lt;STRONG&gt; disabled&lt;/STRONG&gt; on controller side.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - That means that if this is a strong business concern for you ; then you need to contact Cisco &lt;U&gt;&lt;STRONG&gt;(TAC)&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 08:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132449#M272766</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-17T08:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132498#M272772</link>
      <description>&lt;P&gt;IOS-XE 17.3 is effectively end of life:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-xe-17/ios-xe-17-3-x-eol.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-xe-17/ios-xe-17-3-x-eol.html&lt;/A&gt;&amp;nbsp;and had a lot of issues! &lt;BR /&gt;It has already long passed the&amp;nbsp;&lt;STRONG&gt;End of Vulnerability/Security Support&lt;/STRONG&gt;&amp;nbsp;date&amp;nbsp;September 30, 2023!&lt;BR /&gt;This means that even if you find it's a bug it will never be fixed in 17.3.&lt;BR /&gt;There have been hundreds (maybe thousands) of bug fixes since then!&lt;/P&gt;
&lt;P&gt;Refer to the TAC recommended codes link below - you should be running at least 17.9.5 or 17.12.3 now.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 10:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132498#M272772</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-17T10:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132499#M272773</link>
      <description>&lt;P&gt;No new bugs will be investigated or fixed in 17.3 code now.&lt;BR /&gt;If you want to pursue a fix then first upgrade to a currently supported release like 17.9.5 or 17.12.3 and then if you still see the issue open a TAC case for Cisco to investigate further.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 10:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132499#M272773</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-17T10:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132559#M272780</link>
      <description>&lt;P&gt;Ok, thanks I understand. This is a real issue since the FIPS approval from the NIST is only valid on 17.3, except if you indicate me a newer version is FIPS validated ? I have&amp;nbsp;C9120AXE hardware.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 12:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132559#M272780</guid>
      <dc:creator>jguittet</dc:creator>
      <dc:date>2024-06-17T12:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132607#M272782</link>
      <description>&lt;P&gt;It looks to me like FIPS &lt;STRONG&gt;is&lt;/STRONG&gt;&amp;nbsp;certified in 17.6 and 17.9.&amp;nbsp;&amp;nbsp;All certificate details at&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/solutions/industries/government/global-government-certifications/fips-140.html" target="_blank"&gt;https://www.cisco.com/c/en/us/solutions/industries/government/global-government-certifications/fips-140.html&lt;/A&gt;&amp;nbsp;There we see:&lt;/P&gt;
&lt;TABLE id="general-table0" class="general TF" border="0" width="100%" cellspacing="0" cellpadding="1" aria-describedby="id-1716443090448d6s2qvrozvj"&gt;
&lt;TBODY&gt;
&lt;TR class=" odd"&gt;
&lt;TD&gt;Embedded Wireless Controllers on C9100 AP IOS XE 17.9&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://www.cisco.com/c/dam/en_us/solutions/industries/government/security_certification/pdfs/ewc-internal-compliance-letter-17-9-signed.pdf" target="_blank"&gt;2022-08-01&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;17.12 is certified on regular 9800 series WLCs:&lt;/P&gt;
&lt;TABLE id="general-table0" class="general TF" border="0" width="100%" cellspacing="0" cellpadding="1" aria-describedby="id-1716443090448d6s2qvrozvj"&gt;
&lt;TBODY&gt;
&lt;TR class=" odd"&gt;
&lt;TD&gt;Cisco C9800 Wireless Controllers IOS XE 17.12&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://www.cisco.com/c/dam/en_us/solutions/industries/government/security_certification/pdfs/9800-wlc-17-12-compliance-letter-signed.pdf" target="_blank"&gt;2023-11-23&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;and 17.12 on 9100 series APs:&lt;/P&gt;
&lt;TABLE id="general-table0" class="general TF" border="0" width="100%" cellspacing="0" cellpadding="1" aria-describedby="id-1716443090448d6s2qvrozvj"&gt;
&lt;TBODY&gt;
&lt;TR class=" even"&gt;
&lt;TD&gt;Catalyst 9100, Wave 2 and IoT Wireless Access Point IOS XE 17.12&lt;/TD&gt;
&lt;TD&gt;&lt;A href="https://www.cisco.com/c/dam/en_us/solutions/industries/government/security_certification/pdfs/interim-fips-compliance-letter.pdf" target="_blank"&gt;2024-03-06&lt;/A&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;So as far as I can see you could move to 17.9.5 straight away and I suggest you fire off a query to&amp;nbsp;&lt;A href="mailto:certteam@cisco.com" target="_blank"&gt;certteam@cisco.com&lt;/A&gt;&amp;nbsp;about EWC on 17.12 in preparation for the fact that 17.12 will soon become the recommended release train.&amp;nbsp; You can also ask why NIST only lists 17.3.&lt;/P&gt;
&lt;P&gt;Also see:&amp;nbsp;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2024/pdf/BRKEWN-2339.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2024/pdf/BRKEWN-2339.pdf&lt;/A&gt;&amp;nbsp;page 14:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RichR_0-1718631638659.png" style="width: 693px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221019i23B90F4526661A02/image-dimensions/693x104?v=v2" width="693" height="104" role="button" title="RichR_0-1718631638659.png" alt="RichR_0-1718631638659.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 13:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132607#M272782</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-17T13:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132641#M272786</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;thanks so much for this details, this is good news for me.&lt;/P&gt;&lt;P&gt;I will move to 17.9.5 as you suggested.&lt;/P&gt;&lt;P&gt;Latest question on this topic please: I previously asked for a good guide to enable FIPS on the AP but didn't get any answer:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/cisco-software-discussions/activation-of-fips-mode-on-c9120ax-access-point/td-p/5106171" target="_blank"&gt;https://community.cisco.com/t5/cisco-software-discussions/activation-of-fips-mode-on-c9120ax-access-point/td-p/5106171&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you indicate a good reference ?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 14:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132641#M272786</guid>
      <dc:creator>jguittet</dc:creator>
      <dc:date>2024-06-17T14:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132678#M272787</link>
      <description>&lt;P&gt;Just replied with config guide links but one thing in the 17.9 guide caught my attention:&lt;BR /&gt;&lt;EM&gt;- While configuring WLAN ensure that the PSK length must be minimum of 15 characters. If not, the &lt;STRONG&gt;APs will not be able to join the controller&lt;/STRONG&gt; after changing tags.&lt;/EM&gt;&lt;BR /&gt;Don't suppose you had any WLANs with PSK &amp;lt; 15 characters when you enabled FIPS?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 15:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132678#M272787</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-17T15:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: CSCvx84736 - 9115 EWC - Aps won't join when FIPS is enabled.</title>
      <link>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132684#M272788</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt; !! Got the link to the documentation&lt;/P&gt;&lt;P&gt;The PSK was less than 15 characters &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So probably this is the origin of the issue.&lt;/P&gt;&lt;P&gt;I will reset the AP now. You can consider this ticket solved and closed.&lt;/P&gt;&lt;P&gt;Again thanks for your support.&lt;/P&gt;&lt;P&gt;Joel&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 15:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cscvx84736-9115-ewc-aps-won-t-join-when-fips-is-enabled/m-p/5132684#M272788</guid>
      <dc:creator>jguittet</dc:creator>
      <dc:date>2024-06-17T15:21:48Z</dc:date>
    </item>
  </channel>
</rss>

