cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
337
Views
1
Helpful
2
Replies

update web cert on C9800 HA SSO

Charlie Grey
Level 1
Level 1

on the 5500 HA SSO, we need to update the active wlc, perform a redundancy force-switchover, then update the sec wlc certificate.

i was told 5500 wlc need to be reboot for new cert to take effect.

Come to C9800 HA-SSO, does it need a reboot as well? also need to apply to active and force a failover and reapply like 5500 wlc??

search online cannot find any info on this.

thanks.

 

1 Accepted Solution

Accepted Solutions

Rich R
VIP
VIP

@RoadRunner4k has already provided the correct link with full details but addressing your specific questions:

i was told 5500 wlc need to be reboot for new cert to take effect.
Correct

Come to C9800 HA-SSO, does it need a reboot as well?
No but if your read the instructions at that link you'll see you need to restart the https server:

9800(config)#no ip http secure-server
9800(config)#ip http secure-server

 

also need to apply to active and force a failover and reapply like 5500 wlc??
Also answered at that link: "On a 9800 pair configured for Stateful Switchover High Availability  (HA SSO), all certificates are replicated from the primary to the secondary ..." so no need for switchover.

View solution in original post

2 Replies 2

RoadRunner4k
Level 1
Level 1

On the C9800 it doesn't require a reboot as on the 5500 series. 

Generate and Download CSR Certificates on Catalyst 9800 WLCs - Cisco

 

 

 

Rich R
VIP
VIP

@RoadRunner4k has already provided the correct link with full details but addressing your specific questions:

i was told 5500 wlc need to be reboot for new cert to take effect.
Correct

Come to C9800 HA-SSO, does it need a reboot as well?
No but if your read the instructions at that link you'll see you need to restart the https server:

9800(config)#no ip http secure-server
9800(config)#ip http secure-server

 

also need to apply to active and force a failover and reapply like 5500 wlc??
Also answered at that link: "On a 9800 pair configured for Stateful Switchover High Availability  (HA SSO), all certificates are replicated from the primary to the secondary ..." so no need for switchover.

Review Cisco Networking for a $25 gift card