03-07-2018 03:44 AM - edited 07-05-2021 08:21 AM
Greetings
I`m trying to configure LSC on WLC, everything goes OK before the moment when AP tries to establish DTLS connection with WLC.
Output from AP:
CAPWAP State: DTLS Setup
dtls_disconnect: ERROR shutting down dtls connection ...
CAPWAP State: DTLS Teardown
Debug from WLC indicates that problem is with issuer certificate:
sshpmGetCID: Found matching CA cert othSslLscCaCert in row 12
Found CID **** for certname othSslLscCaCert
CACertTable: Found matching CID othSslLscCaCert in row 12 x509 ****
Verify User Certificate: X509 Cert Verification return code: 0
Verify User Certificate: X509 Cert Verification result text: unable to get issuer certificate
Verify User Certificate: Error in X509 Cert Verification at 1 depth: unable to get issuer certificate
X509 OpenSSL Errors...
NONE
OpenSSL Get Issuer Handles: Cert issuer unknown; bailing ...
Certificate verification - failed!
In this document there is an interesting paragraph in which the joining process is described:
Both the LSC CA and the LAP Device certificates are installed into the LAP, and the system self-reboots. The next time it comes up, since it is configured to use LSCs, the AP sends the LSC Device Certificate to the Controller as part of the JOIN Request. As part of the JOIN Response, the controller sends its new Device certificate and also validates the inbound LAP certificate with the new CA Root Certificate.
The question is: how can I upload CA Root Certificate to WLC controller ?
Many thanks
Raul
03-07-2018 04:49 AM
03-07-2018 05:18 AM
Yes, I have Root CA and Sub CA sha2 in infrastructure on Windows 2016 server. On WLC I specified URL, CA and Device certificates was added also. After provisioning AP is rebooting:
Reset Request from Controller(LSC enabled) and after boot AP cannot connect to controller.
03-07-2018 05:32 AM
03-07-2018 05:50 AM
Is it possible the whole chain isn't included in the WLC device cert? - how can I check this ?
(Cisco Controller) >show certificate lsc summary
LSC Enabled...................................... Yes
LSC CA-Server.................................... http://1.1.1.1/certsrv/mscep/mscep.dll
LSC AP-Provisioning.............................. Yes
Provision-List............................... Not Configured
LSC Revert Count in AP reboots............... 3
LSC Params:
Country...................................... ***
State........................................ ***
City......................................... ***
Orgn......................................... ***
Dept......................................... ITI
Email........................................ ***@***.**
KeySize...................................... 2048
LSC Certs:
CA Cert...................................... Present
RA Cert...................................... Not Configured
DEV Cert..................................... Present
(Cisco Controller) >show certificate lsc ap-provision
LSC AP-Provisioning.............................. Yes
Provision-List................................... Present
Idx Mac Address
--- -------------
1 00:27:e3:81:00:00
2 00:27:e3:81:11:11
03-07-2018 07:12 AM
03-12-2019 07:54 AM
Hi, can you please tell me, how you added the device certificate?
Greetings
Gordon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide