cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
922
Views
1
Helpful
7
Replies

Expiring Certificate on Cisco 3700i

DAVID
Level 3
Level 3

I have a Cisco 5520 WLC running 8.10.190 with a mix of of access points connected.  I am in the process of replacing all the Cisco 3702i access points due to EOL and  the expiring  mic certificate.  Unfortunately,  it takes time to order and receive new 9100 series access points.  I had previously done the NTP and set the date time back on the controller and that fixed the issue initially allowed the APs to join the controller at that time.

 

I am now seeing numerous 3072i access points showing up as "disassociated" in Cisco Prime.  A workaround that I have seen is to run the following on the WLC: :  WLC> config ap cert-expiry-ignore mic enable.

 

Will this command allow those APs that are disassociated due to an expiring cert to reconnect to the controller until I can replace AP with 9130 and will it prevent future 3700I APs with expiring certs in the future from not associating to controller ?

2 Accepted Solutions

Accepted Solutions

 

      - Yes ,but use both commands   (for cert and mic)

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

 

            - Negative , the controller just 'honors their certificate'

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

7 Replies 7

marce1000
VIP
VIP

 

(correction)    - For certificate expiration also  add config ap cert-expiry-ignore ssc enable.
       To verify , scrutinize the boot process of an AP afterwards , 

      (edited/added)   You can also find the mentioned commands in 
https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

marce1000
VIP
VIP

 

    - More an item for 'just knowledge'https://community.cisco.com/t5/wireless-mobility-knowledge-base/mic-and-ssc-certificates-expired-on-cisco-ap/ta-p/4720040

    M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

So the short answer is I can use the command to allow the APs to associate to the controller by configuring the controller to  bypass any mic cert expiration while I  replace all the 3700i access points?

 

      - Yes ,but use both commands   (for cert and mic)

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

This will not impact the existing APs that do not have the certificate issue will it?

 

            - Negative , the controller just 'honors their certificate'

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

Also update your software version as per the TAC recommended link below to eliminate any other known bugs which have been fixed - currently recommended version is 8.10.196.0.

Review Cisco Networking for a $25 gift card