Managing AP Certificates
You must get AP certificate replacement before your AP certificate expires. The system generates an apCertificateExpireSystem alarm and event when an AP certificate expires.
For AP Certificate replacement, use the AP certificate replacement tool that allows you to learn information about the APs with a expired certificate and replace the certificates in bulk. To enable the AP certificate replacement:
- Click . This displays the AP Certificate Replacement page.
- By default, the Enable AP Certificate Replacement is disabled. Click the Enable AP Certificate Replacement button to enable the AP certificate replacement and follow the instructions on the screen.
- From the AP Certificate Replacement page, click Import AP certificate Response (.res) file. The Import AP certificate for replacement form appears.
- Click Browse and select the file.
- Click OK.
Note: All APs included in the imported response (.res) file reboot after their certificate is refreshed.
- Select the Zone Name from the drop-down list.
In the AP Certificate section, the following details are displayed.
- Update Stats: Displays the status of the AP certificate.
- AP Request List: Displays the list of requested APs.
- Certificate Status:
Displays the certificate status.If the status is:
- Updating: Controller is in the process of updating the certificate.
- Update Failed:
Controller failed to update the certificate.
Note: The AP reports to the controller at 15-minute intervals. As a result, it may take up to 15 minutes for the AP to update its certificate status on the web interface.
After all the APs are updated with the new certificates, manually enable the
ap-cert-expired-checkCLI command in the config mode to restore security and reject APs that try to connect with expired certificate
%20Access%20Points%20and%20Switch%20Management%20Guide%207.1.1_v2_GUID-7A3AFC5F-36A9-49B9-AF4F-34DB745A36EB/AP_Certificate_Replacement=GUID-090E5704-6662-4649-B185-26BAC9E5EBA8=1=en-US=Low.png)
%20Access%20Points%20and%20Switch%20Management%20Guide%207.1.1_v2_GUID-7A3AFC5F-36A9-49B9-AF4F-34DB745A36EB/AP%20Certificate%20Replacement=GUID-F59B6E61-3119-41AB-BFF5-6AE745DFBF79=1=en-US=Low.gif)