cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2449
Views
0
Helpful
1
Replies

LAP 1142N certificate expired

Hi there,

After a power outage the message bellow appears on my APs. Looks like the certificate has expired.

I’ve verified the date & time on my WLC.
Do I need to upgrade the ios? It's currectly runinng 12.4(18a)JA1.

Are there any workarounds?

*Jan 18 21:58:15.040: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Jan 18 21:58:15.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.96.0.6 peer_port: 5246
*Jan 18 21:58:15.164: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed.
The certificate (SN: 54A93ECE0000000A8662) has expired. Validity period ended on 17:47:34 UTC Dec 28 2016
*Jan 18 21:58:15.165: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Jan 18 21:58:15.165: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Jan 18 21:58:15.165: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:161 Certificate verified failed!
*Jan 18 21:58:15.165: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 10.96.0.6
*Jan 18 21:58:15.166: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 10.96.0.6
*Jan 18 21:58:15.166: %DTLS-3-BAD_RECORD: Erroneous record received from 10.96.0.6: Malformed Certificate
*Jan 18 21:58:15.166: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
*Jan 18 21:59:20.030: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Jan 18 21:59:20.036: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
*Jan 18 21:59:20.037: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down
*Jan 18 21:59:20.038: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
*Jan 18 21:59:20.039: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
*Jan 18 21:59:20.041: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to upwtpDecodeDiscovery Response numOfCapwapDiscoveryResp = 0
wtpDecodeDiscovery Response numOfCapwapDiscoveryResp = 1

Thank you

1 Reply 1

What is the WLC software version. 

Pls check below document & apply the required command.You may need to upgrade your controller to a supported version first

https://supportforums.cisco.com/document/12453081/lightweight-ap-fail-create-capwaplwapp-connection-due-certificate-expiration

HTH

Rasika

*** Pls rate all useful responses ***

Review Cisco Networking for a $25 gift card