<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding custom Root/Issuer PKI certificates to Access Points via WL in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363211#M288280</link>
    <description>&lt;P&gt;Thank you Mark!&lt;BR /&gt;Faton&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jan 2026 10:08:37 GMT</pubDate>
    <dc:creator>Faton-Shala</dc:creator>
    <dc:date>2026-01-20T10:08:37Z</dc:date>
    <item>
      <title>Adding custom Root/Issuer PKI certificates to Access Points via WLC</title>
      <link>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363181#M288278</link>
      <description>&lt;P data-path-to-node="2"&gt;&lt;STRONG data-path-to-node="2" data-index-in-node="0"&gt;Hi everyone,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-path-to-node="3"&gt;I am looking for some guidance on a specific PKI requirement for our Access Points managed by a &lt;STRONG data-path-to-node="3" data-index-in-node="96"&gt;Cisco Catalyst 9800 WLC&lt;/STRONG&gt;.&lt;STRONG data-path-to-node="4" data-index-in-node="0"&gt;The Goal:&lt;/STRONG&gt; I need to distribute and install an &lt;STRONG data-path-to-node="4" data-index-in-node="46"&gt;additional Root and/or Issuer CA certificate&lt;/STRONG&gt; onto the Access Points themselves.&lt;/P&gt;
&lt;P data-path-to-node="5"&gt;Important Clarification:&lt;/P&gt;
&lt;UL data-path-to-node="6"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,0,0"&gt;I am not talking about the SCEP integration to distribute individual device certificates to the APs (that works fine).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="6,2,0"&gt;The goal is specifically to get the Trusted Root/Chain onto the AP’s local truststore so it can validate external services (e.g., for specific authentication or secure syslog/telemetry scenarios).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="7"&gt;My Question: Does anyone know the exact procedure or command set to push a custom CA certificate from the 9800 WLC to the joined APs? Is there a specific "AP Join Profile" setting or a TFTP/HTTP-based method that you have successfully used for this?&lt;/P&gt;
&lt;P data-path-to-node="8"&gt;Any insights or documentation links would be greatly appreciated!&lt;BR /&gt;Best regards,&lt;/P&gt;
&lt;P data-path-to-node="9"&gt;Faton Shala&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 08:56:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363181#M288278</guid>
      <dc:creator>Faton-Shala</dc:creator>
      <dc:date>2026-01-20T08:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Adding custom Root/Issuer PKI certificates to Access Points via WL</title>
      <link>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363208#M288279</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1813917"&gt;@Faton-Shala&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; That cannot be done &lt;FONT color="#FF0000"&gt;&lt;EM&gt;and it is &lt;STRONG&gt;unsupported&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 10:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363208#M288279</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2026-01-20T10:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Adding custom Root/Issuer PKI certificates to Access Points via WL</title>
      <link>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363211#M288280</link>
      <description>&lt;P&gt;Thank you Mark!&lt;BR /&gt;Faton&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 10:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363211#M288280</guid>
      <dc:creator>Faton-Shala</dc:creator>
      <dc:date>2026-01-20T10:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Adding custom Root/Issuer PKI certificates to Access Points via WL</title>
      <link>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363231#M288281</link>
      <description>&lt;P&gt;Thanks for sharing this guide; it’s really helpful to see a clear walk through for adding custom root CA certificates to access points. Steps like these make a big difference for admins trying to ensure secure connections without running into certificate trust issues, and it’s great to have practical, detailed instructions to follow.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 11:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/adding-custom-root-issuer-pki-certificates-to-access-points-via/m-p/5363231#M288281</guid>
      <dc:creator>carlbidwell</dc:creator>
      <dc:date>2026-01-20T11:38:43Z</dc:date>
    </item>
  </channel>
</rss>

