10-21-2022 04:15 AM
Hi all,
I have two Cisco AP AIR-CAP2602I-E-K9 and a Cisco WLC 2500.
WLC is running firmware version 8.5.171.0
In this moment AP and WLC are in the same VLAN.
I get this error messages from Access Point CLI (I connected it to my laptop using serial cable):
%DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:981 Failed to complete DTLS handshake with peer X.X.X.X
*Oct 21 09:45:05.007: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to X.X.X.X:5246
*Oct 21 09:45:05.007: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to X.X.X.X:5246
*Oct 21 09:45:05.007: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
*Oct 21 10:06:57.007: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 5B866A600000001E2FF0) has expired.
Validity period ended on 02:16:14 UTC Feb 23 2022Peer certificate verification failed 001A*Oct 21 10:06:57.007: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:496 Certificate verified failed!
*Oct 21 10:06:57.007: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to X.X.X.X:5246
*Oct 21 10:06:57.007: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to X.X.X.X:5246
I already configured on Cisco WLC these parameters, however nothing change in fact AP are still not registering to WLC.
config ap cert-expiry-ignore mic enable
config ap cert-expiry-ignore ssc enable
I would avoid to change NTP configuration on WLC side.
WLC is running in a production environment so I have to avoid network disservices.
Any suggestions?
Federico
10-21-2022 04:45 AM
10-21-2022 05:06 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs22835 , you may need to fallback to disable NTP and set clock backwards in time.
M.
10-21-2022 08:42 AM
The instructions are all in the field notice but for some reason people can't be bothered to read it and then wonder why they get stuck! So I'll summarise it for the umpteenth time:
1. Upgrade to latest version which supports your APs and WLC - probably 8.5.182.0
https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc10
2. Apply the config workaround on the WLC
3. Disable NTP and set time manually to before your certs expired
4. Allow all the APs to join, download new code, pick up the config workaround
5 Re-enable NTP
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide