<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Location Scanning API - Untrusted Server Certificate in Network Platform API</title>
    <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437122#M5913</link>
    <description>&lt;P data-unlink="true"&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/22774"&gt;@gwangjin.park&lt;/A&gt; just curious are you including the full certificate chain on your server? You'll need to include the full certificate in order for dashboard to connect successfully. You might want to test it with &lt;A href="https://www.ssllabs.com/ssltest/" target="_self" rel="nofollow noopener noreferrer"&gt;SSL Test&lt;/A&gt; to see if any problems are detected with the certificate. If everything checks out then I would definitely agree with &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/23724"&gt;@Christian_Ney&lt;/A&gt; and reach out to support.&lt;/P&gt;&lt;P&gt;This previous &lt;A href="https://community.meraki.com/t5/Developers-APIs/Dashboard-doesn-t-trust-Let-s-Encrypt-Spoiler-Alert-It-does/m-p/48271" target="_self"&gt;thread&lt;/A&gt; might be helpful. &lt;/P&gt;</description>
    <pubDate>Tue, 19 May 2020 00:41:13 GMT</pubDate>
    <dc:creator>cfn</dc:creator>
    <dc:date>2020-05-19T00:41:13Z</dc:date>
    <item>
      <title>Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437120#M5911</link>
      <description>&lt;P&gt;Hi guys!!&lt;/P&gt;&lt;P&gt;I'm going to test the Location Scanning API.&lt;/P&gt;&lt;P&gt;So I prepared an HTTPS server.&lt;BR /&gt;But an error is occurring as shown in the picture below.&lt;/P&gt;&lt;P&gt;- &lt;FONT color="#FF0000"&gt;Untrusted Server Certificate - Please ensure you are using a certificate signed by a valid Certificate Authority(CA)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="error_scanning_api.jpg" style="width: 543px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/262315i7705D157174AE312/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.jpeg" alt="image.jpeg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I don't think there's a problem with the certificate.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert.jpg" style="width: 264px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/262316iD7AA8C20476620F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.jpeg" alt="image.jpeg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please, let me know what can I do.&lt;/P&gt;&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 07:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437120#M5911</guid>
      <dc:creator>gwangjin.park</dc:creator>
      <dc:date>2020-05-18T07:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437121#M5912</link>
      <description>&lt;P&gt;Educated guess: Meraki doesn't trust Sectico certs / at least it seems that they don't have its Pubkey.&lt;/P&gt;&lt;P&gt;Your best option would be calling support.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 15:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437121#M5912</guid>
      <dc:creator>Christian_Ney</dc:creator>
      <dc:date>2020-05-18T15:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437122#M5913</link>
      <description>&lt;P data-unlink="true"&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/22774"&gt;@gwangjin.park&lt;/A&gt; just curious are you including the full certificate chain on your server? You'll need to include the full certificate in order for dashboard to connect successfully. You might want to test it with &lt;A href="https://www.ssllabs.com/ssltest/" target="_self" rel="nofollow noopener noreferrer"&gt;SSL Test&lt;/A&gt; to see if any problems are detected with the certificate. If everything checks out then I would definitely agree with &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/23724"&gt;@Christian_Ney&lt;/A&gt; and reach out to support.&lt;/P&gt;&lt;P&gt;This previous &lt;A href="https://community.meraki.com/t5/Developers-APIs/Dashboard-doesn-t-trust-Let-s-Encrypt-Spoiler-Alert-It-does/m-p/48271" target="_self"&gt;thread&lt;/A&gt; might be helpful. &lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 00:41:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437122#M5913</guid>
      <dc:creator>cfn</dc:creator>
      <dc:date>2020-05-19T00:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437123#M5914</link>
      <description>&lt;P&gt;I solved the problem with your help.&lt;BR /&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;solved&lt;/STRONG&gt;) Import CA certificate to keystore.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 04:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437123#M5914</guid>
      <dc:creator>gwangjin.park</dc:creator>
      <dc:date>2020-05-19T04:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437124#M5915</link>
      <description>&lt;P&gt;I am facing the same issue. The server where we have installed the certificate is linux machine and the CA is Entrust Certfication Authority. I am not sure the issue is with CA whihc is not recognised by Meraki or there is anything else????&lt;/P&gt;&lt;P&gt;When we open the website, the Certificate information and status is OK but once we validate it throws the error.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed to validate with status code: 400, error message:Untrusted Server Certificate – Please ensure you are using a certificate signed by a valid Certificate Authority (CA).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Need very urgent support.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 07:47:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437124#M5915</guid>
      <dc:creator>Ammar-Tanveer01</dc:creator>
      <dc:date>2020-08-13T07:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437125#M5916</link>
      <description>&lt;P&gt;The keystore used by WAS must include CA certificates.&lt;BR /&gt;I will share how to make a keystore that I used.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;(Create keystore file)&lt;/STRONG&gt;&lt;BR /&gt;1. Create a keystore in PKCS12 format with CA certificates.&lt;BR /&gt;    keytool -importcert -keystore [keystore file name] -storepass [password] -storetype PKCS12 -alias rootca -file [Root CA Certification]&lt;BR /&gt;    keytool -importcert -keystore [keystore file name] -storepass [password] -storetype PKCS12 -alias root -file [CA Certification]&lt;BR /&gt;&lt;BR /&gt;2. Convert the SSL certificate to PKCS12 format.&lt;BR /&gt;    openssl pkcs12 -export -in [public key file] -inkey [private key file] -out [cert file name] -name [Any Name]&lt;/P&gt;&lt;P&gt;3. Import certificate in PKCS12 format to keystore&lt;BR /&gt;    keytool -importkeystore -deststorepass [password] -destkeypass [password] -destkeystore [keystore file name] -srckeystore [cert file name] -srcstoretype PKCS12 -srcstorepass [password] -alias [Any Name]&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;ex)&lt;/STRONG&gt;&lt;BR /&gt;   &lt;STRONG&gt;[Certification]&lt;/STRONG&gt;&lt;BR /&gt;   RootCA : USERTrustRSAAddTrustCA.der&lt;BR /&gt;   CA : SectigoRSADomainValidationSecureServerCA.der&lt;BR /&gt;   Public Key : public.key&lt;BR /&gt;   Private Key : private.key&lt;/P&gt;&lt;P&gt;   &lt;STRONG&gt;[Command]&lt;/STRONG&gt;&lt;BR /&gt;   keytool -importcert -keystore keystore.jks -storepass Password1! -storetype PKCS12 -alias rootca -file USERTrustRSAAddTrustCA.der&lt;BR /&gt;   keytool -importcert -keystore keystore.jks -storepass Password1! -storetype PKCS12 -alias root -file SectigoRSADomainValidationSecureServerCA.der&lt;BR /&gt;&lt;BR /&gt;   openssl pkcs12 -export -in public.key -inkey private.key -out mscanning.p12 -name mscanning12&lt;/P&gt;&lt;P&gt;   keytool -importkeystore -deststorepass Password1! -destkeypass Password1! -destkeystore keystore.jks -srckeystore mscanning.p12 -srcstoretype PKCS12 -srcstorepass Password1! -alias mscannings&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 08:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437125#M5916</guid>
      <dc:creator>gwangjin.park</dc:creator>
      <dc:date>2020-08-13T08:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437126#M5917</link>
      <description>&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="CA Issue Meraki1.JPG" style="width: 607px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/262318i4FC8EE8D558331F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.jpeg" alt="image.jpeg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 09:18:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437126#M5917</guid>
      <dc:creator>Ammar-Tanveer01</dc:creator>
      <dc:date>2020-08-13T09:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437127#M5918</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/22774"&gt;@gwangjin.park&lt;/A&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;Just want to know when you encountered the issue, the URL was showing any certificate error? example, were you able to see the valid certificate issue on Website?&lt;/P&gt;&lt;P&gt;Also, the solution you shared is for linux? We are using CentOS.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 09:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437127#M5918</guid>
      <dc:creator>Ammar-Tanveer01</dc:creator>
      <dc:date>2020-08-13T09:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437128#M5919</link>
      <description>&lt;P&gt;I used Tomcat as WAS (Web Application Server).&lt;BR /&gt;This is not affected by the OS.&lt;/P&gt;&lt;P&gt;So, I have some questions.&lt;BR /&gt;&lt;STRONG&gt;Q1&lt;/STRONG&gt;. What does your WAS use?&lt;BR /&gt;      - SSL settings may vary depending on WAS.&lt;BR /&gt;&lt;STRONG&gt;Q2&lt;/STRONG&gt;. Does your keystore contain all certificates (CA)?&lt;BR /&gt;&lt;STRONG&gt;Q3&lt;/STRONG&gt;. Can you send your keystore (with your password)?&lt;BR /&gt;&lt;STRONG&gt;Q4&lt;/STRONG&gt;. Can you show me the error screen from the Meraki dashboard?&lt;/P&gt;&lt;P&gt;I hope your problem will be solved soon.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 23:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437128#M5919</guid>
      <dc:creator>gwangjin.park</dc:creator>
      <dc:date>2020-08-13T23:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Location Scanning API - Untrusted Server Certificate</title>
      <link>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437129#M5920</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;has someone managed to solve? The exact same thing happens to me and I have not been able to solve it&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;"Failed to validate with status code: 400, error message:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;Untrusted Server Certificate – Please ensure you are using a certificate signed by a valid Certificate Authority (CA)"&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;The certificate is issued by ZeroSSL&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 22:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/location-scanning-api-untrusted-server-certificate/m-p/5437129#M5920</guid>
      <dc:creator>maollano</dc:creator>
      <dc:date>2020-08-20T22:58:12Z</dc:date>
    </item>
  </channel>
</rss>

