cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
261
Views
0
Helpful
2
Replies

Re: WLC 2504 Controlller / AIR-CAP2602I-E-K9 / Self Signed Certificate

dmcgrath.ca
Level 1
Level 1

It would appear that there is a new snag to the expiring certificates that I ran into on a WLC 2504 with 8.5.160 and AP's of 3602i and 3702i. Specifically, the WLC certificate expired on Feb 17th 2025 and I guess the APs stay connected until something kicks them off, which happened recently to me.

The usual SSC/MIC ignore expiry problem doesn't apply since it's the WLC that isn't trusted now:

Apr 4 17:26:40.011: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 4FD99CF4000000103486) has expired. Validity period ended on 00:18:54 UTC Feb 17 2025Peer certificate verification failed 001A

The consensus online appears to be to jump the clocks back and disable NTP etc. Any other tips? While it sounds like the 8.5.182.7 might fix this, I am not 100% sure it wouldn't have other issues that reference Wave 1 AP problems or not, but it sounds like I am pretty much stuck at this point, at least without going to a vWLC or similar.

Any advice or tips? It would be nice to NOT have to force an emergency forklift upgrade on the WiFi just yet!

1 Accepted Solution

Accepted Solutions

Rich R
VIP
VIP

That is not new - it was covered in Field Notice FN63942 years ago (link below)!
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuq19142 description specifically says "LAP/WLC MIC or SSC lifetime expiration causes DTLS failure" and WLC cert expiry is covered by Symptom 2 in the notes.  There are a number of other linked bugs for specific corner cases.
The solution hasn't changed - you need to follow ALL the steps in the field notice which means upgrading to latest software release + the cert ignore config.  And it has to be done in the correct order (with setting date back to a date which matches WLC and AP certs before you can do anything else) to get the software and the config applied to every AP.

The software version you should be running is 8.5.182.12 - link below (that's the final release for 2504).

So you don't need a forklift emergency upgrade right now, but that technology is well past sell-by date so you do need to urgently look at upgrading.

View solution in original post

2 Replies 2

Leo Laohoo
Hall of Fame
Hall of Fame

Wind back the date of the WLC to 1 year back.

Once the APs join the WLC, put the correct time and date back on.

Rich R
VIP
VIP

That is not new - it was covered in Field Notice FN63942 years ago (link below)!
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuq19142 description specifically says "LAP/WLC MIC or SSC lifetime expiration causes DTLS failure" and WLC cert expiry is covered by Symptom 2 in the notes.  There are a number of other linked bugs for specific corner cases.
The solution hasn't changed - you need to follow ALL the steps in the field notice which means upgrading to latest software release + the cert ignore config.  And it has to be done in the correct order (with setting date back to a date which matches WLC and AP certs before you can do anything else) to get the software and the config applied to every AP.

The software version you should be running is 8.5.182.12 - link below (that's the final release for 2504).

So you don't need a forklift emergency upgrade right now, but that technology is well past sell-by date so you do need to urgently look at upgrading.

Review Cisco Networking for a $25 gift card