08-29-2023 04:21 AM
I have a Cisco 9800-L WLC (17.3.7) and a signed third party certificate (PKCS#12) issued "godaddy". When I import the certificate it does not work (https not secured in browser) and I get and error message while importing the certificate. When I view the certificate it does not display the CA Certificate associated with the certificate.
What do I do to verify the certificate format/chain I'm importing is correct.
What can I do to import the certificate correctly
08-29-2023 08:34 AM
- Review this documentation : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html
M.
08-30-2023 04:35 AM
Also note you should only use OpenSSL v1.1.1 (latest) not OpenSSL v3.x because the WLC does not support the certs produced by OpenSSL v3.x - see: https://www.wiresandwi.fi/blog/cisco-wlc-9800-certificate-installation-error-reading-file-from-bootflash which references https://community.cisco.com/t5/wireless/wlc-c9800-unable-to-import-pfx-certificate/td-p/4709278/page/2
I asked TAC to update the doc Marce shared a few months ago but they don't seem to have done it yet!
08-30-2023 05:03 AM
We managed to find the problem. The correct keychain was not included with the certificate. We re-chained the certificate using the actual vendor root certificate, intermediate and the actual guest certificate. First we used OpenSSL to rechain the certificate this did not work, and we could not import the certificate to the WLC, however we then used (https://www.sslshopper.com/ssl-converter.html) to rechain the certificate and the certificate worked. Also upgrade the WLC OS to 17.9.3 in the process. Cisco documentation around third party certificates for guest auth on the 9800s not very helpful, most still refer to AirOS which also does not help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide