Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
This looks like a problem with LSC Root Certificate which disallow the AP to build the CAPWAP tunnel with the WLC.Please check if this option- Accept Local Significant Certificate (LSC)enabled under AP policies, if yes, please disable it and test.
...
as far as I have reviewed this looks like a cosmetic issue, the solution is whether restart the AP, the WLC, or both.
Currently, I did no find any documentation or bugs related as this hardly ever happens and after the reboot it solves the issue.
Here is the official cisco guidelines that review IDS signatures in details
Cisco Wireless LAN Controller Configuration Guide || Chapter: Configuring IDS Signatures
https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides...
looks like your WLC certification has expired, to confirm certification has expired run the following command on the WLC:
(Cisco Controller)> show certificate all -> and scroll down until you find this particular certificate and check the Validity En...