07-22-2022 01:20 PM
Hi all,
I have a client with some older Cisco hardware and the certificates stored in their 3600 series APs have recently expired. I'm bypassing the authentication on that front for now so that the network stays up, but I'm looking for a better long-term solution that hopefully doesn't involve purchasing new hardware. I saw on another forum that upgrading the firmware can force the certificates to renew, but I've had very little luck figuring out how to do that. All I can find as far as a manual goes for these APs is a "getting started guide" that doesn't really include any info on managing these devices once they're deployed. Any help you can offer would be appreciated.
Thanks,
Matt
07-22-2022 04:50 PM
A 4500 WLC?
Is this a Sup8/Sup9?
07-25-2022 05:32 AM
The field notice about certs is at https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html
3600 APs are end of support: https://www.cisco.com/c/en/us/products/collateral/wireless/aironet-3600-series/eos-eol-notice-c51-737511.html
Converged access - the short-lived WLC on switch solution you appear to be using - is end of life as Cisco abandoned it. Now superseded by the 9800 series controllers.
Upgrading firmware does not replace the MIC certificate.
Your only option is new hardware because pretty much everything you're using is close to or already past end of support.
07-25-2022 12:37 PM
Thanks, that link gives me a lot of information. I think the update to the fixed software version might be what I found elsewhere, but I couldn't find much in the way of specific instructions. I can get everything else in place, but I'm not sure how to update the devices. I've looked all through the management portal. Any chance you could point me in the right direction?
07-25-2022 05:49 PM
Hi,
Have you tried the following command on the wireless controller:
config ap cert-expiry-ignore {mic|ssc} enable
Thanks
John
07-25-2022 10:15 PM
@johnd2310 this will be IOS-XE - those commands are for AireOS.
@MattP118 I thought you'd already configured the cert expiry workaround?
Generic config for IOS-XE https://www.cisco.com/c/en/us/td/docs/ios/ios_xe/sec_secure_connectivity/configuration/guide/2_xe/sec_secure_connectivity_xe_book/sec_cfg_auth_rev_cert_xe.html
For that old IOS I assume the 9800 config in the field notice should work - otherwise use as a guide and work from there.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: