07-18-2013 06:23 AM - edited 07-04-2021 12:27 AM
Hi all,
we have a lot of problem in joining AP 1600e lightw to a vWLC.
Following the details:
- vWLC: 7.4.100 (with SSC disabled)
- AP: ap1g2-rcvk9w8-tar.152-2.JB
We followed these steps:
- AP directly to vWLC: results: DTLS Error
"*spamApTask3: Jul 18 13:16:26.389: #DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:681 Failed to complete DTLS handshake with peer 10.143.174.200"
- AP to a 7.4 5508 WLC and then to vWLC: results as per previous point
Any clue?
Thanks in advance
Luciano
07-19-2013 06:20 AM
Okay... well verify the country code on the AP matches that on the WLC and then upload a new image to the 1602.
WIRELESS LAN LWAPP RECOVERY
ap1g2-rcvk9w8-tar.152-2.JB.tar
Thanks,
Scott
Help out other by using the rating system and marking answered questions as "Answered"
07-19-2013 07:30 AM
Mhm... That's interesting.
So if your WLC is in Italy, and you have an AP for A regulatory domain, you would not be able to join WLC, because WLC uses Italy country code (Europe). Is there any workaround Scott?
07-19-2013 07:33 AM
you should be able to use multiple country codes.
http://nostringsattachedshow.com/2012/02/02/multiple-country-codes-with-the-cisco-wlc/
HTH,
Steve
------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered
07-19-2013 07:35 AM
Oh , that's true Stephen!
I think this should be a solution for you Luciano Vigano
07-19-2013 08:56 AM
Ciao,
now we are in this situations: the AP is now try to connect to the vWLC
AP: loaded image
ap1g2-k9w8-mx.152-2.JB
Error on vWLC (with US and Canada Country code):
*spamApTask5: Jul 19 15:50:21.290: #DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:681 Failed to complete DTLS handshake with peer 10.143.174.211
Error on AP
*Jul 19 15:52:05.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.143.174.196 peer_port: 5246
*Jul 19 15:52:05.059: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 1000) has expired. Validity period ended on 19:48:03 UTC Dec 14 2010Peer certificate verification failed 001A
*Jul 19 15:52:05.059: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Jul 19 15:52:05.059: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:447 Certificate verified failed!
*Jul 19 15:52:05.059: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 10.143.174.196:5246
*Jul 19 15:52:05.059: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 10.143.174.196:5246
*Jul 19 15:52:05.059: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
07-19-2013 11:02 AM
Ok,
with both RCV and not image still gets this annoing error:
*Jul 19 21:55:30.055: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 1000) has expired. Validity period ended on 19:48:03 UTC Dec 14 2010Peer certificate verification failed 001A
I just set the vWLC time before the date in the error.
AP0006.f6d6.06d1#show crypto pki certificates
CA Certificate
Status: Available
Certificate Serial Number (hex): 00D7D95C4945C3825D
Certificate Usage: General Purpose
Issuer:
cn=CA-vWLC-AIR-CTVM-K9-000C29AC707D
o=Cisco Virtual Wireless LAN Controller
l=San Jose
st=California
c=US
Subject:
cn=CA-vWLC-AIR-CTVM-K9-000C29AC707D
o=Cisco Virtual Wireless LAN Controller
l=San Jose
st=California
c=US
Validity Date:
start date: 19:48:02 UTC Feb 4 2001
end date: 19:48:02 UTC Mar 6 2001
Associated Trustpoints: virtual_wlc_trust_point
Storage:
CA Certificate
Status: Available
Certificate Serial Number (hex): 00
Certificate Usage: General Purpose
Issuer:
cn=ca
ou=none
o=airespace Inc
l=San Jose
st=California
c=US
Subject:
cn=ca
ou=none
o=airespace Inc
l=San Jose
st=California
c=US
Validity Date:
start date: 23:38:55 UTC Feb 12 2003
end date: 23:38:55 UTC Nov 11 2012
Associated Trustpoints: airespace-old-root-cert
Storage:
CA Certificate
Status: Available
Certificate Serial Number (hex): 00
Certificate Usage: Signature
Issuer:
cn=Airespace Root CA
ou=Engineering
o=Airespace Inc.
l=San Jose
st=California
c=US
Subject:
cn=Airespace Root CA
ou=Engineering
o=Airespace Inc.
l=San Jose
st=California
c=US
Validity Date:
start date: 13:41:22 UTC Jul 31 2003
end date: 13:41:22 UTC Apr 29 2013
Associated Trustpoints: airespace-new-root-cert
Storage:
CA Certificate
Status: Available
Certificate Serial Number (hex): 03
Certificate Usage: General Purpose
Issuer:
cn=Airespace Root CA
ou=Engineering
o=Airespace Inc.
l=San Jose
st=California
c=US
Subject:
cn=Airespace Device CA
ou=Engineering
o=Airespace Inc.
l=San Jose
st=California
c=US
Validity Date:
start date: 22:37:13 UTC Apr 28 2005
end date: 22:37:13 UTC Jan 26 2015
Associated Trustpoints: airespace-device-root-cert
Storage:
CA Certificate
Status: Available
Certificate Serial Number (hex): 5FF87B282B54DC8D42A315B568C9ADFF
Certificate Usage: Signature
Issuer:
cn=Cisco Root CA 2048
o=Cisco Systems
Subject:
cn=Cisco Root CA 2048
o=Cisco Systems
Validity Date:
start date: 20:17:12 UTC May 14 2004
end date: 20:25:42 UTC May 14 2029
Associated Trustpoints: Trustpool cisco-root-cert
Storage:
Certificate
Status: Available
Certificate Serial Number (hex): 4B5B3E72000000269099
Certificate Usage: General Purpose
Issuer:
cn=Cisco Manufacturing CA
o=Cisco Systems
Subject:
Name: AP1G2-0006f6d606d1
cn=AP1G2-0006f6d606d1
o=Cisco Systems
l=San Jose
st=California
c=US
CRL Distribution Points:
http://www.cisco.com/security/pki/crl/cmca.crl
Validity Date:
start date: 21:41:51 UTC Mar 4 2013
end date: 21:51:51 UTC Mar 4 2023
Associated Trustpoints: Cisco_IOS_MIC_cert
Storage:
CA Certificate
Status: Available
Certificate Serial Number (hex): 6A6967B3000000000003
Certificate Usage: Signature
Issuer:
cn=Cisco Root CA 2048
o=Cisco Systems
Subject:
cn=Cisco Manufacturing CA
o=Cisco Systems
CRL Distribution Points:
http://www.cisco.com/security/pki/crl/crca2048.crl
Validity Date:
start date: 22:16:01 UTC Jun 10 2005
end date: 20:25:42 UTC May 14 2029
Associated Trustpoints: Trustpool Cisco_IOS_MIC_cert
Storage:
Mybe reinstalling the vWLC ...
07-23-2013 11:43 AM
Finally found the problem!! The SSC was always expired, due to the fact that the ESXi time was xx/xx/2001 !!! It's seems that it is generated during the installation, before configuring the ntp.
WLC reinstalled, now it works fine 🙂
Is there any possibility to regenerate it without reinstall the vWLC??
Sent from Cisco Technical Support Android App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide