04-04-2025 10:32 AM
It would appear that there is a new snag to the expiring certificates that I ran into on a WLC 2504 with 8.5.160 and AP's of 3602i and 3702i. Specifically, the WLC certificate expired on Feb 17th 2025 and I guess the APs stay connected until something kicks them off, which happened recently to me.
The usual SSC/MIC ignore expiry problem doesn't apply since it's the WLC that isn't trusted now:
Apr 4 17:26:40.011: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 4FD99CF4000000103486) has expired. Validity period ended on 00:18:54 UTC Feb 17 2025Peer certificate verification failed 001A
The consensus online appears to be to jump the clocks back and disable NTP etc. Any other tips? While it sounds like the 8.5.182.7 might fix this, I am not 100% sure it wouldn't have other issues that reference Wave 1 AP problems or not, but it sounds like I am pretty much stuck at this point, at least without going to a vWLC or similar.
Any advice or tips? It would be nice to NOT have to force an emergency forklift upgrade on the WiFi just yet!
Solved! Go to Solution.
04-05-2025 03:03 AM
That is not new - it was covered in Field Notice FN63942 years ago (link below)!
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuq19142 description specifically says "LAP/WLC MIC or SSC lifetime expiration causes DTLS failure" and WLC cert expiry is covered by Symptom 2 in the notes. There are a number of other linked bugs for specific corner cases.
The solution hasn't changed - you need to follow ALL the steps in the field notice which means upgrading to latest software release + the cert ignore config. And it has to be done in the correct order (with setting date back to a date which matches WLC and AP certs before you can do anything else) to get the software and the config applied to every AP.
The software version you should be running is 8.5.182.12 - link below (that's the final release for 2504).
So you don't need a forklift emergency upgrade right now, but that technology is well past sell-by date so you do need to urgently look at upgrading.
04-04-2025 04:31 PM
Wind back the date of the WLC to 1 year back.
Once the APs join the WLC, put the correct time and date back on.
04-05-2025 03:03 AM
That is not new - it was covered in Field Notice FN63942 years ago (link below)!
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuq19142 description specifically says "LAP/WLC MIC or SSC lifetime expiration causes DTLS failure" and WLC cert expiry is covered by Symptom 2 in the notes. There are a number of other linked bugs for specific corner cases.
The solution hasn't changed - you need to follow ALL the steps in the field notice which means upgrading to latest software release + the cert ignore config. And it has to be done in the correct order (with setting date back to a date which matches WLC and AP certs before you can do anything else) to get the software and the config applied to every AP.
The software version you should be running is 8.5.182.12 - link below (that's the final release for 2504).
So you don't need a forklift emergency upgrade right now, but that technology is well past sell-by date so you do need to urgently look at upgrading.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide