01-30-2024 09:47 PM
Hi, I'm wanting to upgrade the SW on our 2504 WLC. We are currently experiencing the expired certificate issue where APs are stuck in downloading state.
We do have 2600/3600 APs in our fleet and I understand the last WLC firmware to support these APs is 8.5.x.x.
Ok so based on that, I can upgrade the 2504 SW to 8.5.182.0 and the 2600/3600 APs will be supported?
Current SW is 8.3.143.0, I can upgrade directly to 8.5.182.0 yeah?
Does the 8.5.182.0 (ED) SW fixes the expired certificate issue as mentioned here - IOS AP Image Download Fails Due to Expired Image Signing Certificate Post December 4th, 2022 (CSCwd80290) - Cisco
As summary, is this the correct approach
1. Set this config below on the 2504
config ap cert-expiry-ignore ssc enable
config ap cert-expiry-ignore mic enable
2. Upgrade 2504 to latest FUS version, reboot
3. Upgrade 2504 SW, reboot
thanks
01-30-2024 11:19 PM
So , from that you would need : https://software.cisco.com/download/specialrelease/8f166c6d88b9f77aabb63f78affa9749
8.5.182.0 (ED) doesn't fix it , your procedure is OK ,
M.
01-31-2024 06:32 AM
You should be using 8.5.182.11 (link below) not 8.5.182.0.
Yes you can upgrade directly.
If you're affected by the expired certificates (FN63942) then you will also need to disable NTP and set the time back to before the certs expired to let the APs join, get the updated config from WLC and download updated software. Then once they have the new software and config you can re-enable NTP.
02-01-2024 02:29 PM
thanks guys, much appreciated
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide