<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 2504: Web Auth certificate expires in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672831#M281</link>
    <description>&lt;P&gt;I followed the guide and used Openssl 1.1.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I still get that error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Unbenannt.JPG" style="width: 825px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/15012i61C1CB317B08B870/image-size/large?v=v2&amp;amp;px=999" role="button" title="Unbenannt.JPG" alt="Unbenannt.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jul 2018 09:42:52 GMT</pubDate>
    <dc:creator>as00001111</dc:creator>
    <dc:date>2018-07-24T09:42:52Z</dc:date>
    <item>
      <title>WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3417457#M277</link>
      <description>&lt;P&gt;Hey all!&lt;/P&gt;
&lt;P&gt;I'm using a wlc 2504. There is a third party signed (public signed) certificate for the guest portal.&lt;/P&gt;
&lt;P&gt;Can someone tell me how to recreate that certifcate?&lt;/P&gt;
&lt;P&gt;The current certificate is going to expire in a few days.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3417457#M277</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2021-07-05T15:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3417528#M278</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Take a look here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/wireless-mobility-videos/installing-a-3rd-party-ssl-certificate-for-guest-access/ba-p/3100316" target="_self"&gt;https://supportforums.cisco.com/t5/wireless-mobility-videos/installing-a-3rd-party-ssl-certificate-for-guest-access/ba-p/3100316&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 13:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3417528#M278</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-07-18T13:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672755#M279</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;When I want do define a challenge password during the csr, I get:&amp;nbsp;&amp;nbsp; (openssl 0.9.8)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pwerror.PNG" style="width: 964px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14992iC91294DC600C8555/image-size/large?v=v2&amp;amp;px=999" role="button" title="pwerror.PNG" alt="pwerror.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I decided to do it without a challenge password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when I want to download my final-cert.pem into the wlc, I get that:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Unbenannt.JPG" style="width: 825px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/14994i9BC568F72D3E3108/image-size/large?v=v2&amp;amp;px=999" role="button" title="Unbenannt.JPG" alt="Unbenannt.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you help me?&lt;/P&gt;
&lt;P&gt;Do I need a challenge password?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 08:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672755#M279</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2018-07-24T08:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672774#M280</link>
      <description>&lt;P&gt;Please follow this posts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 08:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672774#M280</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2018-07-24T08:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672831#M281</link>
      <description>&lt;P&gt;I followed the guide and used Openssl 1.1.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I still get that error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Unbenannt.JPG" style="width: 825px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/15012i61C1CB317B08B870/image-size/large?v=v2&amp;amp;px=999" role="button" title="Unbenannt.JPG" alt="Unbenannt.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 09:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672831#M281</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2018-07-24T09:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672873#M282</link>
      <description>&lt;P&gt;I get that in the debug log:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*TransferTask: Jul 24 12:50:56.055: sshpmAddWebauthCert: Extracting private key from webauth cert and using bundled pkcs12 password.&lt;BR /&gt;&lt;BR /&gt;*TransferTask: Jul 24 12:50:56.066: sshpmDecodePrivateKey: private key decode failed...&lt;BR /&gt;&lt;BR /&gt;*TransferTask: Jul 24 12:50:56.066: sshpmAddWebauthCert: key extraction failed.&lt;BR /&gt;&lt;BR /&gt;*TransferTask: Jul 24 12:50:56.066: RESULT_STRING: Error installing certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 11:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672873#M282</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2018-07-24T11:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672988#M283</link>
      <description>&lt;P&gt;Which version of WLC code are you running?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the error message, it seems it can't decode the Private Key. Is it correctly attached to the PKCS12 file? Sometimes this needs to be enabled on the signing server.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 11:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672988#M283</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2018-07-24T11:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672995#M284</link>
      <description>&lt;P&gt;I'm running 8.0.110.0&lt;/P&gt;
&lt;P&gt;Yes, it is attached.&lt;/P&gt;
&lt;P&gt;Could the 2048 bits be a problem? Do I need 1024 bits?&lt;/P&gt;
&lt;P&gt;Could the openssl version be a problem?&lt;/P&gt;
&lt;P&gt;How many cert levels can I use? I got 2 Intermediate CAs and 1 Root CA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 11:39:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3672995#M284</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2018-07-24T11:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673014#M285</link>
      <description>You are running a VERY old version of software on your controller. It's well possible that this version doesn't even support 2048 bit certificates or has a bug with them. In any case, I'd first upgrade to the latest 8.0 or better 8.2 or 8.5 (depending on what AP models you are using, some old models were dropped in 8.5 and I think 8.2).&lt;BR /&gt;There is also a second bug in your version that will not allow APs manufactured 2007 and older to connect anymore, because of another certificate issue. &lt;BR /&gt;&lt;BR /&gt;Also check this:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/wireless-security-and-network/cannot-install-webauth-cert-on-5508-wlc/td-p/2924301" target="_blank"&gt;https://community.cisco.com/t5/wireless-security-and-network/cannot-install-webauth-cert-on-5508-wlc/td-p/2924301&lt;/A&gt;&lt;BR /&gt;Do you have the Root and Intermediate certificates already installed? I think you first need to install those and then the final certificate.&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Jul 2018 11:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673014#M285</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2018-07-24T11:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673021#M286</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Do you have the Root and Intermediate certificates already installed? I think you first need to install those and then the final certificate.&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;No, I don't.&lt;/P&gt;
&lt;P&gt;How can I install them?&lt;/P&gt;
&lt;P&gt;I thought this is done by placing them into the cained certificate&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 11:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673021#M286</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2018-07-24T11:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673028#M287</link>
      <description>Good question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Here another manual on how to chain them correctly:&lt;BR /&gt;&lt;A href="https://knowledge.digicert.com/solution/SO25994.html" target="_blank"&gt;https://knowledge.digicert.com/solution/SO25994.html&lt;/A&gt;&lt;BR /&gt;And here another way on how to chain:&lt;BR /&gt;&lt;A href="http://www.my80211.com/cisco-wlc-cli-commands/2011/1/16/wlcgenerate-third-party-web-authentication-certificate-for-a.html" target="_blank"&gt;http://www.my80211.com/cisco-wlc-cli-commands/2011/1/16/wlcgenerate-third-party-web-authentication-certificate-for-a.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;So I actually think you have to correctly chain them. Also it seems 2048 bit should be supported.</description>
      <pubDate>Tue, 24 Jul 2018 11:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673028#M287</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2018-07-24T11:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673048#M288</link>
      <description>&lt;P&gt;Or do you think I just have to upload the single server cert?&lt;/P&gt;
&lt;P&gt;(unchained)&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 12:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673048#M288</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2018-07-24T12:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673062#M289</link>
      <description>No, all manuals state the cert needs to be chained, correctly chained. You might need to check this in an editor (notepad++) and check if really the right certificate comes first in the file.</description>
      <pubDate>Tue, 24 Jul 2018 12:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673062#M289</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2018-07-24T12:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504: Web Auth certificate expires</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673064#M290</link>
      <description>&lt;P&gt;okay.&lt;/P&gt;
&lt;P&gt;I have already taken a look at both of these manuals.&lt;/P&gt;
&lt;P&gt;Manual 1 describes to use a challenge password; manual 2 doesn't.&lt;/P&gt;
&lt;P&gt;That's one point of confusion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Point 2:&lt;/P&gt;
&lt;P&gt;Since I got two intermediate ca's, my chain looks like that:&lt;/P&gt;
&lt;P&gt;----BEGIN CERTIFICATE ----&lt;BR /&gt; ‘Server certificate ’&lt;BR /&gt; ---- END CERTIFICATE ----&lt;BR /&gt; ---- BEGIN CERTIFICATE ----&lt;BR /&gt; ‘Intermediate CA certificate’&lt;BR /&gt; ---- END CERTIFICATE ----&lt;/P&gt;
&lt;P&gt;---- BEGIN CERTIFICATE ----&lt;BR /&gt; ‘Intermediate CA certificate’&lt;BR /&gt; ---- END CERTIFICATE ----&lt;BR /&gt; ---- BEGIN CERTIFICATE ----&lt;BR /&gt; ‘Root CA certificate’&lt;BR /&gt; ---- END CERTIFICATE ----&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit: It worked, don't know what I did different now. But it works &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The cert created with openssl 0.9.8 and without a challenge password.&lt;/P&gt;
&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 12:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-web-auth-certificate-expires/m-p/3673064#M290</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2018-07-24T12:27:51Z</dc:date>
    </item>
  </channel>
</rss>

