08-10-2024 07:44 AM
I have a Cisco 5520 WLC running 8.10.190 with a mix of of access points connected. I am in the process of replacing all the Cisco 3702i access points due to EOL and the expiring mic certificate. Unfortunately, it takes time to order and receive new 9100 series access points. I had previously done the NTP and set the date time back on the controller and that fixed the issue initially allowed the APs to join the controller at that time.
I am now seeing numerous 3072i access points showing up as "disassociated" in Cisco Prime. A workaround that I have seen is to run the following on the WLC: : WLC> config ap cert-expiry-ignore mic enable.
Will this command allow those APs that are disassociated due to an expiring cert to reconnect to the controller until I can replace AP with 9130 and will it prevent future 3700I APs with expiring certs in the future from not associating to controller ?
Solved! Go to Solution.
08-10-2024 09:26 AM
- Yes ,but use both commands (for cert and mic)
M.
08-10-2024 10:57 AM
- Negative , the controller just 'honors their certificate'
M.
08-10-2024 08:18 AM - edited 08-10-2024 08:21 AM
(correction) - For certificate expiration also add config ap cert-expiry-ignore ssc enable.
To verify , scrutinize the boot process of an AP afterwards ,
(edited/added) You can also find the mentioned commands in
https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html
M.
08-10-2024 08:25 AM
- More an item for 'just knowledge' : https://community.cisco.com/t5/wireless-mobility-knowledge-base/mic-and-ssc-certificates-expired-on-cisco-ap/ta-p/4720040
M.
08-10-2024 08:53 AM
So the short answer is I can use the command to allow the APs to associate to the controller by configuring the controller to bypass any mic cert expiration while I replace all the 3700i access points?
08-10-2024 09:26 AM
- Yes ,but use both commands (for cert and mic)
M.
08-10-2024 10:24 AM
This will not impact the existing APs that do not have the certificate issue will it?
08-10-2024 10:57 AM
- Negative , the controller just 'honors their certificate'
M.
08-11-2024 04:39 PM
Also update your software version as per the TAC recommended link below to eliminate any other known bugs which have been fixed - currently recommended version is 8.10.196.0.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide