cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
15784
Views
42
Helpful
23
Replies

WLC C9800 - Unable to import pfx Certificate

stephendrkw
Level 3
Level 3

Hi all, 

I'm unable to import a PCKS12 Device Mgmt certificate into my Wireless Controller C9800, unlike my previous 5508 WLC's there are now Trustpoints etc involved.

The way we generate Certificates is we do not generate a CSR from the Device, rather input device details manually on a Cert Server GUI and this generates a.pfx file we download. We would import this .pfx onto the device and bang! Cert installs successfully just like on my 5508's! 

C9800 log:

Oct 25 08:23:37.190: CRYPTO_PKI: status = 0x705(E_INPUT_DATA : invalid encoding format for input data): Imported PKCS12 file failure
Oct 25 08:23:37.192: %PKI-3-PKCS12_IMPORT_FAILURE: PKCS #12 import failed for trustpoint: C9800.hello.com.pfx. Reason: Failed to import pkcs12 context

I don't want to connect to our CA Server as there are so many hurdles internally to use SCEP. Is there a way to import a .pfx into C9800 directly without a Trustpoint. Every time I create a Trustpoint, C9800 forces me to authenticate to a CA Server. Also, I am surprised the logs are complaining about invalid encoding format, aren't p12 and pfx are the same (PCKS#12) depending how your server generates them.

23 Replies 23

stephendrkw
Level 3
Level 3

"debug pki transaction" ouput below, to me this indicates that the import pfx is trying to use the Cisco Self-Signed Trustpoint and failing?

Oct 25 09:24:56.260: CRYPTO_PKI: Rcvd request to end PKI session A3FE3.
Oct 25 09:24:56.260: CRYPTO_PKI: PKI session A3FE3 has ended. Freeing all resources.TP-self-signed-146588143:unlocked trustpoint TP-self-signed-146588143, refcount is 0
Oct 25 09:24:56.309: CRYPTO_PKI: Initializing renewal timers
Oct 25 09:24:56.312: CRYPTO_PKI: (A3FE5) Session started - identity selected (TP-self-signed-146588143)xTP-self-signed-146588143:refcount after increment = 1
Oct 25 09:24:56.312: CRYPTO_PKI: Begin local cert chain retrieval.
Oct 25 09:24:56.313: CRYPTO_PKI: Done with local cert chain fetch 0.
Oct 25 09:24:56.313: CRYPTO_PKI: Begin trustpoint info get.
Oct 25 09:24:56.313: CRYPTO_PKI: Successfully got trustpoint info.
Oct 25 09:24:56.313: CRYPTO_PKI: (93FE6) Session started - identity selected (TP-self-signed-146588143)TP-self-signed-146588143:refcount after increment = 2
Oct 25 09:24:56.313: CRYPTO_PKI: Begin local cert chain retrieval.
Oct 25 09:24:56.313: CRYPTO_PKI: Done with