cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
25821
Views
6
Helpful
8
Replies

config ap cert-expiry-ignore {mic|ssc} enable

daswann
Level 1
Level 1

We found a couple of old 1141N AP's in our network that were not associated with the controller. Upon investigation I found that the MIC had expired. We are currently running 8.3.133 on the controllers. If this command is used in the shot term, (until I can replace them with new models)  it will only be relevant to AP's with an expired MIC and not affect any other AP's from what I have read correct? Also would this leave them open to man-in-the middle attacks? Thank in advance!

1 Accepted Solution

Accepted Solutions

marce1000
VIP
VIP

 

 - Yes, that is correct, those with valid certs (not expired) will not be prone to man-in-the-middle attacks.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

View solution in original post

8 Replies 8

marce1000
VIP
VIP

 

 - Yes, that is correct, those with valid certs (not expired) will not be prone to man-in-the-middle attacks.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Thank you M. just wanted to make sure. I will be replacing the access points tomorrow so I won't need to use the command but wanted a second set of eyes on it.

Hi Marce - Do you know if the older APs "with expired" certs will be vulnerable to MIMs?

 

thanks 

Hello Marce,

 

Hello, I have a Cisco WLC 2504 with version 7.6.130.0 but both commands below are not available:
Command for Version 7.0.252.0:
config ap lifetime-check {mic|ssc} enable
Command for Versions 7.4.140.0 and later:
config ap cert-expiry-ignore {mic|ssc} enable
 
Please help
Thank you,

- You need at least 8.3.x for that.

M.


-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

RHEA LINN
Level 1
Level 1

How do you determine the MIC on the expired AP?

 

      AP_CLI#sh crypto pki certificates

         Look for the line containing end date

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

AP_CLI#sh crypto pki certificates

 

Does the AP check?
Does WLC check?

If I use config ap cert-expiry-ignore mic enable on WLC 5520 model, is AP OK in MIC authentication?

Review Cisco Networking products for a $25 gift card