cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
542
Views
10
Helpful
2
Replies

WLC 2054 webauth cert

Jeff_
Level 1
Level 1

Hello,


My company has a CISCO WLC 2504 that is complaining about webauth certificate.
I've found that the certificate has expired and the regenerated one doesn't let people connect.
I tried to upload a new certificate, but it gives me some errors.
Well, I've already tried to create the certificate as chained and encoded, tried with password and without it,

Just to add, I've already followed these "how-to":
https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html#anc8
https://community.cisco.com/t5/wireless-security-and-network/wlc-2504-web-auth-certificate-expires/m-p/3673028#M54878

So, do I really need to use openssl0.9.8?

Could someone help me?

 

Below, the debug pm pki + debug transfer


==================================================================


[...]
*TransferTask: May 26 19:09:45.481: TFP End: 7722 bytes transferred (0 retransmitted packets)

*TransferTask: May 26 19:09:45.481: tftp rc=0, pHost=x.x.x.x pFilename=/something.pem
pLocalFilename=cert.p12

*TransferTask: May 26 19:09:45.481: RESULT_STRING: TFTP receive complete... Installing Certificate.

*TransferTask: May 26 19:09:45.481: RESULT_CODE:13


TFTP receive complete... Installing Certificate.
*TransferTask: May 26 19:09:49.485: Adding cert (7662 bytes) with certificate key password.

*TransferTask: May 26 19:09:49.520: sshpmCheckWebauthCert: Verification return code: 1

*TransferTask: May 26 19:09:49.521: Verification result text: ok

*TransferTask: May 26 19:09:49.531: sshpmAddWebauthCert: Extracting private key from webauth cert and using bundled pkcs12 password.

*TransferTask: May 26 19:09:49.538: sshpmDecodePrivateKey: private key decode failed...

*TransferTask: May 26 19:09:49.539: sshpmAddWebauthCert: key extraction failed.

*TransferTask: May 26 19:09:49.539: RESULT_STRING: Error installing certificate.


*TransferTask: May 26 19:09:49.540: RESULT_CODE:12


==================================================================

1 Accepted Solution

Accepted Solutions

Jeff_
Level 1
Level 1
So, I've already solved this problem

For people who does have any problem like this one, try to use openssl0.9.8zb.
Tried with some other versions that didn't help me at all.
Thanks anyways.

View solution in original post

2 Replies 2

Scott Fella
Hall of Fame
Hall of Fame
I have always stuck with v9.8 to be honest. I know that later version have worked, but I just don’t have time to keep generating certs and testing them. The link you have is fine and as long as you bundled the cert properly it should work. Make sure that the VIP with the FQDN matches the certificate and that the FQDN can be validated by the DNS servers the guest are using via DHCP.
-Scott
*** Please rate helpful posts ***

Jeff_
Level 1
Level 1
So, I've already solved this problem

For people who does have any problem like this one, try to use openssl0.9.8zb.
Tried with some other versions that didn't help me at all.
Thanks anyways.
Review Cisco Networking products for a $25 gift card