<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Wes ... in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700298#M6088</link>
    <description>&lt;P&gt;Hi Wes ...&lt;/P&gt;
&lt;P&gt;Did you get the solution of this situation ? Now i m on the same situation .. can u please guide ,me on the same please ??&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2016 10:51:56 GMT</pubDate>
    <dc:creator>saror0001</dc:creator>
    <dc:date>2016-04-28T10:51:56Z</dc:date>
    <item>
      <title>Updating webauth certificate within 5508 WLC HA pair</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700296#M6086</link>
      <description>&lt;P&gt;I am looking for some clarification before I go ahead and install/reboot my 5508 WLC pair.&lt;/P&gt;&lt;P&gt;The webauth certificate is about to expire so I have chained a new cert together. I have dual 5508s in HA mode and have uploaded the cert. I am now faced with a reboot.&lt;/P&gt;&lt;P&gt;However, I can't find any information online about updating certs within an HA pair, all I can find mentioning certs is in the "Configuring High Availability" section of the "Cisco Wireless LAN Controller Configuration Guide" which states "Certificates should be downloaded separately on each controller before they are paired." Does this still apply when WLCs are already in HA mode?&lt;/P&gt;&lt;P&gt;Has anyone here updated a cert within an HA pair and if so have you simply issued a reboot command when the cert is downloaded to the controller? Surely I don't have to break the pair apart to install the new cert on both then join together again?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Wes&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700296#M6086</guid>
      <dc:creator>wesdouglas</dc:creator>
      <dc:date>2021-07-05T10:32:39Z</dc:date>
    </item>
    <item>
      <title>Hi Wes,This is a limitation</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700297#M6087</link>
      <description>&lt;P&gt;Hi Wes,&lt;/P&gt;&lt;P&gt;This is a limitation in WLC HA. you have to install the certificates on both of&amp;nbsp; the Controllers.&lt;/P&gt;&lt;P&gt;When you do the web auth certificate installation on WLC which is in HA pair, the cert will be pushed only on Primary Controller. After the fail over to secondary, the guest clients will receive the "certificate warning" until the primary takes over.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Divya&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 07:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700297#M6087</guid>
      <dc:creator>Divya</dc:creator>
      <dc:date>2015-07-17T07:04:43Z</dc:date>
    </item>
    <item>
      <title>Hi Wes ...</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700298#M6088</link>
      <description>&lt;P&gt;Hi Wes ...&lt;/P&gt;
&lt;P&gt;Did you get the solution of this situation ? Now i m on the same situation .. can u please guide ,me on the same please ??&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 10:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700298#M6088</guid>
      <dc:creator>saror0001</dc:creator>
      <dc:date>2016-04-28T10:51:56Z</dc:date>
    </item>
    <item>
      <title>The upload of the webauth</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700299#M6089</link>
      <description>&lt;P&gt;The upload of the webauth certificate only happens on the active unit. Once the certificate has been uploaded for the first (primary) controller you need to reload &lt;STRONG&gt;only&lt;/STRONG&gt; that unit so the secondary controller is going to be the active one. Wait for the HA set to be active again, upload the certificate again and reboot that&lt;STRONG&gt; &lt;/STRONG&gt;unit as well. Once that reboot has been done HA is active again and you are done.&lt;BR /&gt;&lt;BR /&gt;If you do it this way there should be no impact, but personally I would still arrange a service-window just to make sure.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Please rate useful posts... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2016 14:39:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700299#M6089</guid>
      <dc:creator>Freerk Terpstra</dc:creator>
      <dc:date>2016-05-14T14:39:17Z</dc:date>
    </item>
    <item>
      <title>Device and root certificates</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700300#M6090</link>
      <description>&lt;P&gt;Device and root certificates are not automatically synced to the Standby controller. you have to manually break HA or make failover to apply on secondary.&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2016 01:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/2700300#M6090</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2016-05-16T01:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Updating webauth certificate within 5508 WLC HA pair</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/3697687#M6091</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to update on this one, though this post is very old.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Scenario:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;=======&lt;/P&gt;
&lt;P&gt;Uploading new WebAuth cert for Cisco WLC 5520 HA pair and 5508 two standalone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#0000FF"&gt;Solution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;=======&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;1) Standalone two 5508s were straightforward&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;a) upload the cert and&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;b) reboot&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;2) HA pair 5580&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; a) upload cert on ACTIVE&amp;nbsp;one first. This WLC would be one which is being accessed by default on the management interface. Cert will be pushed to the ACTIVE WLC first and ask for the reboot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; b) reboot the WLC. In doing so, &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;HOT STANDBY&lt;/FONT&gt;&lt;/STRONG&gt; will become&lt;STRONG&gt;&lt;FONT color="#008000"&gt; ACTIVE&lt;/FONT&gt;&lt;/STRONG&gt;. ( monitor the management&amp;nbsp;interface via ping and you'll notice no ping lose)&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; c) Monitor two WLCs via three Pings to see what is happening&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; i) continuous&amp;nbsp;ping to the &lt;STRONG&gt;Management interface&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ii) continuous ping to the &lt;STRONG&gt;Redundancy Mgmt Interface&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; iii) continuous&amp;nbsp;ping to the &lt;STRONG&gt;Peer Redundancy Mgmt Interface&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; d) When ACTIVE&amp;nbsp;WLC is back through&amp;nbsp;the ping let it settle down, then check the webAuth&amp;nbsp;cert via CLI command &lt;U&gt;&lt;STRONG&gt;'Show certificate webauth'&lt;/STRONG&gt;&lt;/U&gt; on both WLCs&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; e) now ACTIVE would be the one that was HOT STANDBY, this would still have the old cert. Upload the&amp;nbsp;cert on to this one and reboot. While doing this you'll see no ping drop on 'Management Interface'&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; f) After this WLC comes back it becomes HOT STANDBY, exactly the role it had before starting this exercise. Smooth isn't it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; g) Check cert has been upload on both by above CLI command. &lt;FONT color="#FF00FF"&gt;Happy days!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;Kind regards,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;B&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 08:52:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/3697687#M6091</guid>
      <dc:creator>Beacon Bits</dc:creator>
      <dc:date>2018-08-30T08:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Updating webauth certificate within 5508 WLC HA pair</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/4024737#M6092</link>
      <description>&lt;P&gt;Hi Beacon,&lt;/P&gt;&lt;P&gt;This information is very helpful,&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 08:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/4024737#M6092</guid>
      <dc:creator>Prkalavadia</dc:creator>
      <dc:date>2020-02-06T08:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Updating webauth certificate within 5508 WLC HA pair</title>
      <link>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/4081450#M6093</link>
      <description>&lt;P&gt;With the HA pair running code level 8.3 (or higher) and self-generating the CSR file, can I load the same .pem file on both contollers in the pair?&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2020 18:41:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/updating-webauth-certificate-within-5508-wlc-ha-pair/m-p/4081450#M6093</guid>
      <dc:creator>brianalster</dc:creator>
      <dc:date>2020-05-07T18:41:47Z</dc:date>
    </item>
  </channel>
</rss>

