<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CA Certs for 5520 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869472#M30210</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/860798"&gt;@craigshawm6&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure that certificate you're installing is having the complete chain.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 13:46:12 GMT</pubDate>
    <dc:creator>Sathiyanarayanan Ravindran</dc:creator>
    <dc:date>2019-06-07T13:46:12Z</dc:date>
    <item>
      <title>CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3868961#M30205</link>
      <description>&lt;P&gt;Our existing 5508 wlcs have "othIpsecCaCert" for IPSec and "bsnSslEapCaCert" for EAP Certificates. Our HA Pair of 5520 show nothing in the "security, advanced, Vendor Certs" area. Just blank. How do I get these created?&lt;/P&gt;&lt;P&gt;Running 8.5.140.0&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3868961#M30205</guid>
      <dc:creator>craigshawm6</dc:creator>
      <dc:date>2021-07-05T17:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869088#M30206</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/860798"&gt;@craigshawm6&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration is same as other models and versions. Please refer this for&amp;nbsp;&lt;A title="Local EAP" href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/100590-ldap-eapfast-config.html#wlc" target="_blank" rel="noopener"&gt;Local EAP&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 18:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869088#M30206</guid>
      <dc:creator>Sathiyanarayanan Ravindran</dc:creator>
      <dc:date>2019-06-06T18:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869112#M30207</link>
      <description>&lt;P&gt;I have everything set, except it gives me an error for installing the IPsec CA certificate. The other 3 installed and worked just fine.&amp;nbsp;IPSEC Device, EAP Device, and EAP CA worked great. Just the IPSec CA won't upload/install. I've tried two different certs. I've ran OpenSSL as an administrator. Nothing is working for this last cert install.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OUTPUT BELOW:&lt;/P&gt;&lt;P&gt;TFTP IPSEC CA cert transfer starting.&lt;/P&gt;&lt;P&gt;TFTP receive complete... installing Certificate.&lt;/P&gt;&lt;P&gt;Error installing certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 12:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869112#M30207</guid>
      <dc:creator>craigshawm6</dc:creator>
      <dc:date>2019-06-07T12:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869442#M30208</link>
      <description>&lt;P&gt;before installing cert, can you enable &lt;STRONG&gt;debug transfer all enable&amp;nbsp;and debug pm pki&lt;/STRONG&gt; &lt;STRONG&gt;enable&lt;/STRONG&gt; and install again and paste the debug output.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 13:01:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869442#M30208</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2019-06-07T13:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869461#M30209</link>
      <description>&lt;P&gt;(Cisco Controller) &amp;gt;debug transfer all enable&lt;/P&gt;&lt;P&gt;(Cisco Controller) &amp;gt;debug pm pki enable&lt;/P&gt;&lt;P&gt;(Cisco Controller) &amp;gt;*emWeb: Jun 07 09:35:23.142: [PA] file name=&lt;/P&gt;&lt;P&gt;*emWeb: Jun 07 09:35:23.142: [PA] total size=0&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:23.142: [PA] Memory overcommit policy changed from 0 to 1&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:23.142: [PA] RESULT_STRING: TFTP IPSEC CA cert transfer starting.&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:23.142: [PA] RESULT_CODE:1&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.157: [PA] TFTP: Binding to remote=172.21.30.136&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.180: [PA] TFP End: 11686 bytes transferred (0 retransmitted packets)&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.180: [PA] tftp rc=0, pHost=172.21.30.136 pFilename=./wlcIPSecCACert.pem&lt;BR /&gt;pLocalFilename=cert.p12&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.195: [PA] RESULT_STRING: TFTP receive complete... installing Certificate.&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.195: [PA] RESULT_CODE:13&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.195: [PA] Adding cert (11594 bytes) with certificate key password.&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.195: [PA] sshpmCheckCaCertBasicConsrtaints: CA Certificate basic constraint check failed at depth 0&lt;BR /&gt;*TransferTask: Jun 07 09:35:27.195: [PA] Add IPSEC CA certificate: Error checking basic constraints (verify: YES) IPSEC CA certificate chain&lt;BR /&gt;*TransferTask: Jun 07 09:35:27.195: [PA] RESULT_STRING: Error installing certificate.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;*TransferTask: Jun 07 09:35:27.195: [PA] RESULT_CODE:12&lt;/P&gt;&lt;P&gt;*TransferTask: Jun 07 09:35:27.195: [PA] Memory overcommit policy restored from 1 to 0&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 13:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869461#M30209</guid>
      <dc:creator>craigshawm6</dc:creator>
      <dc:date>2019-06-07T13:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869472#M30210</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/860798"&gt;@craigshawm6&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ensure that certificate you're installing is having the complete chain.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 13:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869472#M30210</guid>
      <dc:creator>Sathiyanarayanan Ravindran</dc:creator>
      <dc:date>2019-06-07T13:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869476#M30211</link>
      <description>&lt;P&gt;Not sure how to do that exactly. I followed the exact same process for the other 3 certs that were installed on the wlc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 13:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869476#M30211</guid>
      <dc:creator>craigshawm6</dc:creator>
      <dc:date>2019-06-07T13:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869558#M30212</link>
      <description>If you open the certificate in a text editor, it should contain two or more ***BEGIN CERTIFICATE*** (or similar) areas. One for the root, zero or more for the intermediates and lastly the actual certificate.</description>
      <pubDate>Fri, 07 Jun 2019 15:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869558#M30212</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-06-07T15:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869562#M30213</link>
      <description>&lt;P&gt;I see three different "begin certificate" when I opened it in notepad. Each has it's corresponding "end certificate" as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 15:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869562#M30213</guid>
      <dc:creator>craigshawm6</dc:creator>
      <dc:date>2019-06-07T15:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869667#M30214</link>
      <description>Decode all by using &lt;A href="https://www.sslshopper.com/certificate-decoder.html" target="_blank"&gt;https://www.sslshopper.com/certificate-decoder.html&lt;/A&gt;</description>
      <pubDate>Fri, 07 Jun 2019 18:37:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869667#M30214</guid>
      <dc:creator>Sathiyanarayanan Ravindran</dc:creator>
      <dc:date>2019-06-07T18:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869671#M30215</link>
      <description>&lt;P&gt;All three certs checked good on that link. Everything looks on the up and up. It just won't install.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will it affect not having the IPSec CA Cert installed?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 19:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3869671#M30215</guid>
      <dc:creator>craigshawm6</dc:creator>
      <dc:date>2019-06-07T19:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3870348#M30216</link>
      <description>&lt;P&gt;So what is the effect of not having the IPSec CA cert on the 5520? The other 3 certs, IPSec Device, EAP CA, and EAP Device, installed just fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 15:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3870348#M30216</guid>
      <dc:creator>craigshawm6</dc:creator>
      <dc:date>2019-06-10T15:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3870387#M30217</link>
      <description>Sorry I can't help you, never installed a cert on the Wlc.&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Jun 2019 16:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3870387#M30217</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-06-10T16:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: CA Certs for 5520</title>
      <link>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3886758#M30218</link>
      <description>&lt;P&gt;sorry for the late reply.&lt;/P&gt;&lt;P&gt;The WLC uses IPSec to protect traffic to Radius server and syslog server.&lt;/P&gt;&lt;P&gt;you don't necessarily have to use it, but its off course recommended and I think its mandatory for CC compliance.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 05:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ca-certs-for-5520/m-p/3886758#M30218</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2019-07-09T05:15:06Z</dc:date>
    </item>
  </channel>
</rss>

