02-13-2019 12:49 AM - edited 07-05-2021 09:50 AM
Generating a chained SHA2 certificate for Web Authentication with OpenSSL version 1.0.1e-fips and installing on a Cisco 5508 WLC running firmware version 8.2.170.0 successful.
The installation of the same certificate(s) on a Cisco 5508 WLC running firmware version 8.0.152.0 NOT successful.
What is the required OpenSSL version assuming that 8.0.152.0 does support SHA2 certificates?
Failing with the installation of the mentioned certificate(s) on a 8.0.152.0 WLC: Is this eventually based on another reason and/or bug?
Is there a compatibility matrix (OpenSSL | WLC firmware version | SHA2 support) available/defined?
02-13-2019 01:10 AM
Hi,
Note: OpenSSL Version 0.9.8 is the recommended version for old WLC releases;
Regards
Dont forget to rate helpful posts
02-13-2019 03:51 AM
Thank you.
However Cisco is saying: OpenSSL Version 0.9.8 is the recommended version for old WLC releases; however, as of Version 7.5, support for OpenSSL Version 1.0 was also added (refer to Cisco bug ID CSCti65315 - Need Support for certificates generated using OpenSSL v1.0) and is the recommended version to use. OpenSSL 1.1 works was also tested and works great on 8.x and later WLC releases.
Other question: Does version 8.0.152.0 support Chained SHA2 Certificates?
02-13-2019 03:58 AM
As per my info, The WLC supports SHA-2 certificates since release 8.0.100.0
https://itigloo.com/security/generate-an-openssl-certificate-request-with-sha-256-signature/
Regards
Dont forget to rate helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide