<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problems loading a Certificate in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680261#M90357</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;My customer has generated a certificate following this document:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The key length is 2048 instead of 1024.&lt;/P&gt;&lt;P&gt;the Upload of the final file on a 5508 (7.6.110.0) ends in this message:„File transfer failed“.&lt;/P&gt;&lt;P&gt;in the Log he finds this:&lt;/P&gt;&lt;P&gt;„#UPDATE-3-CERT_INST_FAIL: updcode.c:2140 Failed to install certificate. rc = 2”&lt;/P&gt;&lt;P&gt;Does anybody has an idea what may be wrong here?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Willem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 10:16:28 GMT</pubDate>
    <dc:creator>Willem de Groot</dc:creator>
    <dc:date>2021-07-05T10:16:28Z</dc:date>
    <item>
      <title>Problems loading a Certificate</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680261#M90357</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;My customer has generated a certificate following this document:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The key length is 2048 instead of 1024.&lt;/P&gt;&lt;P&gt;the Upload of the final file on a 5508 (7.6.110.0) ends in this message:„File transfer failed“.&lt;/P&gt;&lt;P&gt;in the Log he finds this:&lt;/P&gt;&lt;P&gt;„#UPDATE-3-CERT_INST_FAIL: updcode.c:2140 Failed to install certificate. rc = 2”&lt;/P&gt;&lt;P&gt;Does anybody has an idea what may be wrong here?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Willem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680261#M90357</guid>
      <dc:creator>Willem de Groot</dc:creator>
      <dc:date>2021-07-05T10:16:28Z</dc:date>
    </item>
    <item>
      <title>What was used to create the</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680262#M90358</link>
      <description>&lt;P&gt;What was used to create the CSR? If you used open SSL make sure you use a version less than 1.0v. If you did make sure you order the root, chain and device cert properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2015 13:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680262#M90358</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-05-21T13:29:11Z</dc:date>
    </item>
    <item>
      <title>Hi Georgethe final-cert.pem</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680263#M90359</link>
      <description>&lt;P&gt;Hi George&lt;/P&gt;&lt;P&gt;the final-cert.pem looks like this.&lt;/P&gt;&lt;P&gt;Is this the correct order of the chain?&lt;/P&gt;&lt;P&gt;Ofcourse, I deleted the Certficates and change the customer name.&lt;/P&gt;&lt;P&gt;Bag Attributes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; localKeyID: a hex key&lt;BR /&gt;subject=/C=CH/ST=a-State/L=a-Place/O=Customer AG/OU=IPM/CN=guest-wlan.Customer.com&lt;BR /&gt;issuer=/C=US/O=thawte, Inc./CN=thawte SSL CA - G2&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;some text&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;Bag Attributes: &amp;lt;Empty Attributes&amp;gt;&lt;BR /&gt;subject=/C=US/O=thawte, Inc./CN=thawte SSL CA - G2&lt;BR /&gt;issuer=/C=US/O=thawte, Inc./OU=Certification Services Division/OU=(c) 2006 thawte, Inc. - For authorized use only/CN=thawte Primary Root CA&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;some text&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;Bag Attributes: &amp;lt;Empty Attributes&amp;gt;&lt;BR /&gt;subject=/C=US/O=thawte, Inc./OU=Certification Services Division/OU=(c) 2006 thawte, Inc. - For authorized use only/CN=thawte Primary Root CA&lt;BR /&gt;issuer=/C=ZA/ST=Western Cape/L=Cape Town/O=Thawte Consulting cc/OU=Certification Services Division/CN=Thawte Premium Server CA/emailAddress=premium-server@thawte.com&lt;BR /&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;some text&lt;BR /&gt;-----END CERTIFICATE-----&lt;BR /&gt;Bag Attributes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; localKeyID: a hex key&lt;BR /&gt;Key Attributes: &amp;lt;No Attributes&amp;gt;&lt;BR /&gt;-----BEGIN ENCRYPTED PRIVATE KEY-----&lt;BR /&gt;Proc-Type: 4,ENCRYPTED&lt;BR /&gt;DEK-Info: DES-EDE3-CBC,sometext&lt;/P&gt;&lt;P&gt;some text&lt;BR /&gt;-----END ENCRYPTED PRIVATE KEY-----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2015 13:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680263#M90359</guid>
      <dc:creator>Willem de Groot</dc:creator>
      <dc:date>2015-05-21T13:39:36Z</dc:date>
    </item>
    <item>
      <title>The exact same certificate</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680264#M90360</link>
      <description>&lt;P&gt;The exact same certificate that was loading fine in 7.4.121.0 does not work any more in 7.6.130.0.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 May 2015 18:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680264#M90360</guid>
      <dc:creator>olivier.nicolas</dc:creator>
      <dc:date>2015-05-24T18:39:35Z</dc:date>
    </item>
    <item>
      <title>I had exactly the same issue.</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680265#M90361</link>
      <description>&lt;P&gt;I had&amp;nbsp;exactly the same issue. Was advised to downgrade the WLC from 7.6 to 7.4. Install cert and then upgrade back to 7.6. But hardly ideal....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2015 20:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680265#M90361</guid>
      <dc:creator>serotonin888</dc:creator>
      <dc:date>2015-06-01T20:51:37Z</dc:date>
    </item>
    <item>
      <title>The certificate bundle was</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680266#M90362</link>
      <description>&lt;P&gt;The certificate bundle was working in 7.4 but installation of the same cert bundle fails in 7.6.&lt;/P&gt;&lt;P&gt;Enabling the PKI debug, shows the following error.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&amp;gt; debug pm pki enable&lt;BR /&gt;&amp;gt; transfer download start&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;TFTP receive complete... Installing Certificate.&lt;BR /&gt;*TransferTask: Jun 15 13:12:25.068: sshpmCheckWebauthCert: Verification return code: 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;*TransferTask: Jun 15 13:12:25.068: Verification result text: unable to get issuer certificate&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;*TransferTask: Jun 15 13:12:25.068: &lt;SPAN style="color:#FF0000;"&gt;Error at 1 depth: unable to get issuer certificate&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;*TransferTask: Jun 15 13:12:25.075: sshpmAddWebauthCert: Error decoding certificate, Deleting it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;Error installing certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;AireOS 7.6 complains that the cert bundle does not contains the cert chain up to the root CA (depth 1 is the intermediate CA)&lt;/P&gt;&lt;P&gt;Until now (7.4), I didn't&amp;nbsp; include the top level root and it was fine.&lt;/P&gt;&lt;P&gt;So, I add the top level root certificate to the cert bundle and restart the transfer successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;TFTP receive complete... Installing Certificate.&lt;BR /&gt;*sshpmLscTask: Jun 15 13:13:15.736: sshpmLscTask: LSC Task received a message 4&lt;BR /&gt;*TransferTask: Jun 15 13:13:40.245: sshpmCheckWebauthCert: Verification return code: 1&lt;BR /&gt;*TransferTask: Jun 15 13:13:40.245: Verification result text: ok&lt;BR /&gt;*TransferTask: Jun 15 13:13:40.254: sshpmAddWebauthCert: Extracting private key from webauth cert and using bundled pkcs12 password.&lt;BR /&gt;*TransferTask: Jun 15 13:13:42.361: sshpmDecodePrivateKey: calling ssh_skb_decode()...&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.461: sshpmDecodePrivateKey: SshPrivateKeyPtr after skb_decode: 0x2c14d454&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.461: sshpmAddWebauthCert: got private key; extracting certificate...&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.466: sshpmAddWebauthCert: extracted binary cert; doing x509 decode&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.466: sshpmAddWebauthCert: doing x509 decode for 1322 byte certificate...&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.470: sshpmAddWebauthCert: freeing x509 certificate...&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.470: sshpmAddWebauthCert: adding cert/key to id table; current/max: 5/7&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.470: sshpmGetIdCertIndex: called to lookup cert &amp;gt;bsnSslWebauthCert&amp;lt;&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.470: sshpmGetIdCertIndex: found match in row 4&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.470: sshpmAddWebauthCert: deleting bsnSslWebauthCert (row 4)&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.471: sshpmAddWebauthCert: freeing cert (fn: 0x10c903c8).&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.471: sshpmAddWebauthCert: freeing key (fn: 0x11d54e14).&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.471: sshpmAddWebauthCert: adding new cert to row 4 (bsnSslWebauthCert).&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.471: sshpmAddWebauthCert: writing cert to /mnt/application/bsnSslWebauthCert.crt&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.471: sshpmWriteCredentialFile: called to write &amp;lt;/mnt/application/bsnSslWebauthCert.crt&amp;gt;; certptr 0x2cd599c0, length 1322&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.471: sshpmAddWebauthCert: exporting private key&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.475: sshpmAddWebauthCert: writing key to /mnt/application/bsnSslWebauthCert.prv&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.475: sshpmWriteCredentialFile: called to write &amp;lt;/mnt/application/bsnSslWebauthCert.prv&amp;gt;; certptr 0x2cd58958, length 1192&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.475: sshpmAddWebauthCert: Unlinking the previously created P12-PEM file webauth_p12.pem&lt;BR /&gt;*TransferTask: Jun 15 13:13:44.475: sshpmAddWebauthCert: Created File webauth_p12.pem&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;Certificate installed.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reboot the switch to use new certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 13:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680266#M90362</guid>
      <dc:creator>olivier.nicolas</dc:creator>
      <dc:date>2015-06-15T13:42:26Z</dc:date>
    </item>
    <item>
      <title>Hi all,The problem is solved</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680267#M90363</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;The problem is solved!&lt;/P&gt;&lt;P&gt;Thawte has changed his root certificate even the old one was valid till 2020.&lt;/P&gt;&lt;P&gt;after getting the latest root certificate, the install worked, even on 7.6.110.0.&lt;/P&gt;&lt;P&gt;before using the new rootcertificate, using:&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;EM&gt;(Cisco Controller) &amp;gt;debug pm pki enable&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;we got the following output:&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;EM&gt;TFTP receive complete... Installing Certificate.&lt;BR /&gt;*TransferTask: Jun 18 09:54:13.276: sshpmCheckWebauthCert: Verification return code: 0&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;EM&gt;*TransferTask: Jun 18 09:54:13.276: Verification result text: unable to get issuer certificate&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;EM&gt;*TransferTask: Jun 18 09:54:13.276: Error at 2 depth: unable to get issuer certificate&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;EM&gt;*TransferTask: Jun 18 09:54:13.288: sshpmAddWebauthCert: Error decoding certificate, Deleting it.&lt;/EM&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;EM&gt;Error installing certificate.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;the at 2 depth can be due to a intermediate-CA in between&lt;/P&gt;&lt;P&gt;Thanks all&lt;/P&gt;&lt;P&gt;Willem (and Customer)&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 11:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680267#M90363</guid>
      <dc:creator>Willem de Groot</dc:creator>
      <dc:date>2015-06-18T11:54:32Z</dc:date>
    </item>
    <item>
      <title>I ran in the same issue. The</title>
      <link>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680268#M90364</link>
      <description>&lt;P&gt;I ran in the same issue. The chain bundle provided from Thawte seems to be wrong&lt;/P&gt;
&lt;P&gt;https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;amp;actp=CROSSLINK&amp;amp;id=AR2051&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;After changing the root to the first one of this list, it worked for me&lt;/P&gt;
&lt;P&gt;https://www.thawte.com/roots/Q&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;best regards&lt;/P&gt;
&lt;P&gt;Alfred&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 09:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/problems-loading-a-certificate/m-p/2680268#M90364</guid>
      <dc:creator>alfred.thyri</dc:creator>
      <dc:date>2017-07-07T09:17:15Z</dc:date>
    </item>
  </channel>
</rss>

