01-13-2025 06:31 AM
I have a problem with logs:
Jan 13 07:48:02.617: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 3D7B23) has expired. Validity period ended on 2024-11-23T08:00:03Z
Jan 13 08:48:02.703: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 3D7B23) has expired. Validity period ended on 2024-11-23T08:00:03Z
Jan 13 08:48:02.795: %PKI-4-TRUSTPOOL_DOWNLOAD_FAILURE: Trustpool Download failed
I have a Cisco 9800-CL with 17.12.04 - SMU-PATCHED
How can I verify it? I have checked all the certificates and they seem to be up to date.
01-13-2025 06:40 AM - edited 01-13-2025 06:42 AM
Did you install certificate on the WLC or it is self-signed?
There is a bug with similar behavior
https://bst.cisco.com/bugsearch/bug/CSCvz30488?rfs=qvlogin
01-13-2025 06:45 AM
self-signed
01-13-2025 07:14 AM
- I would advise that you generate the self-signed certificate again :
Ref: https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html
>...There are extra considerations needed for the 9800-CL as the virtual appliance doesn’t come with a Manufacture Installed Certificate. It needs a Self Signed Certificate (SSC) to terminate CAPWAP tunnel from the AP. Follow the steps below to generate an SSC for a 9800-CL:
M.
01-13-2025 10:07 AM
Did you do any change on the trustpool configuration of the WLC?
A new WLC and with new IOS you should not have problem with certificate.
Take a look on this guide
01-13-2025 06:42 AM
- Ref : https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/trustpoints/b-configuring-trustpoints-on-cisco-catalyst-9800-series-controllers/m-troubleshoot-common-issues-for-certificate-configuration.html
Look up the particular error and read on:
M.
01-13-2025 06:52 AM
Show wireless management trustpoint <<- share this
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide