cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1054
Views
11
Helpful
16
Replies

Cisco WLC 2500 Certificate Expiration Workaround

aaron-rousch
Level 1
Level 1

Good Day.

I have a Cisco 2500 Series Wireless Controller and i have come across the issue in the Field Notice: FN63942 

Following the instructions Situation: The WLC runs fixed software, but some APs cannot join.

  1. Enter the config ap cert-expiry-ignore {mic|ssc} enable command.
  2. If any of the APs that cannot join have not downloaded the fixed software
    1. Disable NTP.
    2. Set the clock back to a time before the WLC certificate expired (might keep newer APs from joining).
    3. Have all APs join the WLC, download new software, and rejoin.
    4. Set the clock to the correct time and re-enable NTP.

i have followed the steps as instructed and i have an Air-CAP3702P-A-K9 that still refuses to join. I get the same error

"%PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 6732C08E0000001FA741) has expired. Validity period ended on 04:53:04 UTC Oct 30 2024Peer certificate verification failed 001A"

I can confirm that the Certificate The certificate (SN: 6732C08E0000001FA741) is on the WLC and not the AP

I an unable to download any software from Cisco due to not having a Service License

Is there a step i missed?

Any help would be appreciated. 

Thank you for your time.

PS: if this is not the correct place to put this question. Please let me know and i will remove this post and re-ask the question in the appropriate place.

 

 

16 Replies 16

Good Day Rich. I tried to email TAC as you suggested, but it seems that TAC email is no longer available

the email states 

"

Thank you for contacting Cisco Technical Assistance Center (TAC) Support.

 

Please be advised that the email alias tac@cisco.com is no longer monitored, as we have transitioned to a more streamlined support system to enhance our service quality and response time.

To open a new case or manage an existing case with Cisco TAC, go to Support Case Manager (SCM):

i tried to open a TAC support case but the AP and WLC has reached end of life and it will not allow me to create a case.

Ah then I guess you'll have to do it over the phone - they don't make things easier!

Review Cisco Networking for a $25 gift card