<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C9800 pki auth error in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279545#M282302</link>
    <description>&lt;P&gt;Yes you can configure additional country codes on the controller.&amp;nbsp; That should then fix your issue.&amp;nbsp; Just make sure the ap is mounted in the country its made for so that you don't break any regulations.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Apr 2025 00:22:11 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2025-04-09T00:22:11Z</dc:date>
    <item>
      <title>C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279410#M282284</link>
      <description>&lt;P&gt;Access points are not authenticating on&amp;nbsp;&lt;SPAN&gt;Cisco Catalyst 9800-40 Wireless Controller&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;17.9.5.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Monitoring &amp;gt; Wireless &amp;gt; AP Statistics -&amp;gt; No reboot reason |&amp;nbsp;&lt;SPAN&gt;AP Auth Failure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;AP models:&amp;nbsp;&lt;SPAN&gt;C9130AXI-Z and IW6300&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Trace logs: Attached&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Any suggestion?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 16:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279410#M282284</guid>
      <dc:creator>fabio daitx</dc:creator>
      <dc:date>2025-04-08T16:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279417#M282285</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1502792"&gt;@fabio daitx&lt;/a&gt;&amp;nbsp;Can you provide more info?&amp;nbsp; Do you have any other access points connected or is this a new setup?&amp;nbsp; You have NTP configured on the controller and also validated the country code configuration?&amp;nbsp; Have you tried to put the ap on the same subnet as the controller?&amp;nbsp; These are just basic things to look at and try.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 16:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279417#M282285</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-04-08T16:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279419#M282286</link>
      <description>&lt;P&gt;Few things -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Are you really doing AP auth?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;2025/04/08 12:50:18.740673830 {wncd_x_R0-2}{2}: [errmsg] [16528]: (note): %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: R0/2: wncd: AP Event: AP Name: AP4006.D5E0.2180 Mac: 4006.d5cb.d440 Session-IP: 10.135.148.191[5256] 10.201.233.81[5246] Disjoined AP Auth Failure&lt;BR /&gt;&lt;BR /&gt;Please check from WLC GUI &amp;gt; Configuration &amp;gt; Security &amp;gt; AAA &amp;gt; AAA Advanced &amp;gt; AP Policy ====&amp;gt; and check if you have enabled AP authz. Also if enabled, if that's an intended config (If not, disable that). If intended config, then please check if the AP base ethernet mac address is added to your authz database. Usually AP Auth is mostly used in mesh setup. Refer -&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;2. Looks like you are running 9800-40 on 17.9.5. According to the trace it looks like 'CISCO_IDEVID_SUDI' trustpoint might be in use for the WMI. Please note that there is a change in SUDI cert happened in 17.9.5. Refer -&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/release-notes/rn-17-9-9800.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/release-notes/rn-17-9-9800.html&lt;/A&gt;&amp;nbsp;(Table 1).&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 16:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279419#M282286</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-04-08T16:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279421#M282287</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Adding to '&lt;STRONG&gt;basic things&lt;/STRONG&gt;' being mentioned ; validate the 9800-40 controller's &lt;STRONG&gt;configuration&lt;/STRONG&gt; with the&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;CLI command &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech &lt;U&gt;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt; and feed the output from that into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 16:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279421#M282287</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-04-08T16:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279434#M282289</link>
      <description>&lt;P&gt;Answers:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;Do you have any other access points connected or is this a new setup?&lt;/EM&gt; Yes, have other aps and are working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;You have NTP configured on the controller and also validated the country code configuration?&lt;/EM&gt; Yes, NTP is working. How dow I validate the country code configuration?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;&amp;nbsp;Have you tried to put the ap on the same subnet as the controller?&lt;/EM&gt; It is not possible, the controller is remotely connected, but now there is also one ap that is in the same subnet and not working.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 17:08:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279434#M282289</guid>
      <dc:creator>fabio daitx</dc:creator>
      <dc:date>2025-04-08T17:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279444#M282291</link>
      <description>&lt;P&gt;Answers:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;1. Are you really doing AP auth?&lt;/EM&gt; No, I was not supposed to do that. I had enabled that to try making AP authenticate and associate with controller, but now I have just disabled AP Policy -&amp;gt;Authorize APs against MAC (disabled) |&amp;nbsp;Authorize APs against Serial Number (disable) and two other APs associated. Thanks. Now I have only one AP that is not associating, IW6300 (new log attached). It worked once but never more after I configure as bridge (I have already tryed reseting factory defaults, but still not working).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;2. Looks like you are running 9800-40 on 17.9.5.&lt;/EM&gt; I am not sure about&amp;nbsp;'CISCO_IDEVID_SUDI', what am I supposed to do? Change some configuration? How can I do that?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 17:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279444#M282291</guid>
      <dc:creator>fabio daitx</dc:creator>
      <dc:date>2025-04-08T17:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279445#M282292</link>
      <description>&lt;P&gt;For the country code, you would see the model in the sticker on the access point or on the box.&amp;nbsp; Now to check what country code you have configured already, you can reference this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/country-codes.html#config-country-codes" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/country-codes.html#config-country-codes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;As long as the ap's you have purchased are the same country as the existing ones that are already joined and working to that controller, then the country code is not the issue.&amp;nbsp; Also, looking at the Wireless Matrix,&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html," target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html,&lt;/A&gt;&amp;nbsp;The ap model you posted is supported on that 9800 code your also posted.&amp;nbsp; Given that you already have existing access points jined to that controller eliminates any issue with the trustpoint.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So what model access point do you have that are successfully joined to that controller and do you have existing access points that are joined on the same switch as the ones you are not able to join?&amp;nbsp; This also helps eliminate an infrastructure issues with either local mode or flexconnect mode.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 17:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279445#M282292</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-04-08T17:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279456#M282294</link>
      <description>&lt;P&gt;I am still seeing AP Auth failure in the logs..since you have disabled the AP Authz, WLC should allow the AP. Now I am more interested to look into these outputs from the AP CLI -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#show capwap client rcb&lt;/P&gt;
&lt;P&gt;#show capwap client config&lt;/P&gt;
&lt;P&gt;#show ip int br&lt;/P&gt;
&lt;P&gt;#show logging&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 17:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279456#M282294</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-04-08T17:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279459#M282296</link>
      <description>&lt;P&gt;Done. No big insight about the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 18:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279459#M282296</guid>
      <dc:creator>fabio daitx</dc:creator>
      <dc:date>2025-04-08T18:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279464#M282297</link>
      <description>&lt;P&gt;It follows attached.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 18:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279464#M282297</guid>
      <dc:creator>fabio daitx</dc:creator>
      <dc:date>2025-04-08T18:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279467#M282298</link>
      <description>&lt;P&gt;IW-6300H-AC-Z-K9 is not listed for Brazil. Since it is the only AP that is not working now, I suppose that it can be related to country code. Can I configure multiple country codes, like for example BR and US in order that model to work? Obs.: I intend to use mesh in future.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 18:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279467#M282298</guid>
      <dc:creator>fabio daitx</dc:creator>
      <dc:date>2025-04-08T18:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279544#M282301</link>
      <description>&lt;P&gt;I am sorry! Looks like the logs are collected from controller. As mentioned, the commands shared before need to be run in the problematic AP.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 00:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279544#M282301</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-04-09T00:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279545#M282302</link>
      <description>&lt;P&gt;Yes you can configure additional country codes on the controller.&amp;nbsp; That should then fix your issue.&amp;nbsp; Just make sure the ap is mounted in the country its made for so that you don't break any regulations.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2025 00:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5279545#M282302</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-04-09T00:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5280118#M282340</link>
      <description>&lt;P&gt;AP auth is &lt;STRONG&gt;mandatory&lt;/STRONG&gt; for bridge mode APs &amp;lt;wink&amp;gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html&lt;/A&gt;&lt;BR /&gt;"A mesh AP &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;needs to be authenticated&lt;/STRONG&gt; &lt;/FONT&gt;for it to join the 9800 controller."&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 11:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5280118#M282340</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-04-10T11:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5280206#M282360</link>
      <description>&lt;P&gt;Hi, I just solved the problem by manually loggin in the ap and issuing the following command:&amp;nbsp;&lt;SPAN&gt;"capwap ap mode local" as described at&amp;nbsp;&lt;A href="https://community.cisco.com/t5/wireless/wlc-9800-l-c-ap-iw-6300h-not-join/td-p/4278159" target="_blank"&gt;https://community.cisco.com/t5/wireless/wlc-9800-l-c-ap-iw-6300h-not-join/td-p/4278159&lt;/A&gt;. I didn't understand why aps were associating as bridge, if they factory default reseted. Anyway I also collected the logs (attached) and now I am running the mesh configuration procedure (&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html&lt;/A&gt;). Thanks for your help and support.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 15:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5280206#M282360</guid>
      <dc:creator>fabio daitx</dc:creator>
      <dc:date>2025-04-10T15:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 pki auth error</title>
      <link>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5280212#M282361</link>
      <description>&lt;P&gt;I think what you need to look at is to factory reset it again and see if it goes back to bridge.... that might be something you need to document as that might of been set at the factory.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 15:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-pki-auth-error/m-p/5280212#M282361</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-04-10T15:54:02Z</dc:date>
    </item>
  </channel>
</rss>

