cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1690
Views
80
Helpful
2
Replies

Windows 11 fail on WLC WebAuth

Hi all!

 

I have a problem with Windows 11 (and also some recent versions of Windows 10).

Apparently, when they try to connect to a managed SSID with WebAuth locally on the WLC, they get this screen:

 

2022-03-04 09_27_41-Image 1 (002).png

 

 

 

 

 

 

Doing a "debug web-auth redirect enable mac", I get these logs:

 

* webauthRedirect: Feb 28 15: 38: 17.757: 80: 19: 34: e0: 89: f4- Web-auth type Internal, no further redirection needed. Presenting defualt login page to user

* webauthRedirect: Feb 28 15: 38: 17.757: 80: 19: 34: e0: 89: f4- added redirect =, URL is now https://guest.candy.it/login.html?
* webauthRedirect: Feb 28 15: 38: 17.757: 80: 19: 34: e0: 89: f4- str1 is now https://guest.candy.it/login.html?redirect=ctldl.windowsupdate.com/msdownload/ update / v3 / static / trustedr / en / disallowedcertstl.cab? f81ef29b3f20f822
* webauthRedirect: Feb 28 15: 38: 17.757: 80: 19: 34: e0: 89: f4- clen string is Content-Length: 398

* webauthRedirect: Feb 28 15: 38: 17.757: 80: 19: 34: e0: 89: f4- Message to be sent is
HTTP / 1.1 200 OK
Location: https://guest.candy.it/login.html?redirect=ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedce
* webauthRedirect: Feb 28 15: 38: 17.757: 80: 19: 34: e0: 89: f4- 200 send_data = HTTP / 1.1 200 OK

 

It is possible that they are linked to the Windows Automatic Root Certificates Update service, as described in the paragraph "How to Disable / Enable Automatic Root Certificates Update in Windows?" of the following page?

 

http://woshub.com/updating-trusted-root-certificates-in-windows-10/

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

Not sure if this resolves the issue, quick try installing that Certificate locally on one of the PC and test it ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

For the WebAuth we are using the embedded certificate:

 

2022-03-04 10_45_03-Window.png

 

I noticed in one of the logs this message:

 

*webauthRedirect: Feb 28 15:38:17.757: 80:19:34:e0:89:f4- str1 is now https://guest.candy.it/login.html?redirect=ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f81ef29b3f20f822

I believe the client simply cannot reach this address ...