<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Onboarding ICX switch to SZ/vSZ with Error: HTTP Response Code 400 in RUCKUS Self-Help</title>
    <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Onboarding-ICX-switch-to-SZ-vSZ-with-Error-HTTP-Response-Code/m-p/54777#M99</link>
    <description>&lt;P&gt;Are you having trouble to onboard an ICX switch into your SmartZone controller?&lt;/P&gt;
&lt;P&gt;Check the logs in the ICX switch with the command 'show log', if you see errors like these below, it's very likely there's a certificate issue between the ICX and the controller:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Jun 24 18:32:02:I:MGMT Agent: Failed to connect to network controller at 192.168.169.220 Error: HTTPS Connection Error&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Jun 24 18:31:42:I:MGMT Agent: Failed to connect to network controller at 192.168.169.220 Error: JSON Parse Error&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Jun 24 18:31:42:I:MGMT Agent: Failed to connect to network controller at 192.168.169.220 Error: HTTP Response Code 400&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;This error is common when working with 'non-TPM' switches, which means the switch uses &lt;STRONG&gt;self-signed certificates&lt;/STRONG&gt;. Switch models with this charatieristic are&amp;nbsp;&lt;SPAN&gt;ICX 7250, ICX 7450, or ICX 7750. Check your switch's certificate using the CLI comand 'dm verify-device-certs' as shown below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;SSH@ICX-7450#dm verify-device-certs&lt;BR /&gt;Commencing sanity check for device certs ...&lt;BR /&gt;Verifying files on Non-TPM Platform ...&lt;BR /&gt;Successfully verified&lt;BR /&gt;The device key pair is valid&lt;BR /&gt;The Encrypt/Decrypt test is successful&lt;BR /&gt;Successfully verified device certs&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;How to resolve this? There is a CLI command that you can run in SZ/vSZ to honor this kind of self-signed certificates of non-TPM switches.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;1. Log into the CLI of your controller using SSH and run the following commands.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ# config&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ(config)# non-tpm-switch-cert-validate&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Successful operation&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ(config)# exit&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ#&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;2. Your switch should now be onboarded.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Visit RUCKUS &lt;A href="https://docs.commscope.com/en-US/bundle/sz-600-cliguide-sz300/page/GUID-8B740B78-C390-4B7B-A271-6A511179B68A.html" target="_blank" rel="noopener"&gt;online documentation&lt;/A&gt; for more information about this CLI command.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;If the switch's certificate is corrupted or not valid, regenerate the certificates using the below two steps (this is only for non-TPM devices):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;a) Zeroize the current keys&lt;/SPAN&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; ICX(config)# crypto device-key-zeroize&lt;BR /&gt;&amp;nbsp; &amp;nbsp; ICX(config)# crypto device-cert-zeroize&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;SPAN&gt;b) Reload the ICX device&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;For TPM devices, we cannot regenerate a new cert through CLI, so you need to RMA the device if the certificate is corrupted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Visit RUCKUS &lt;A href="https://docs.commscope.com/en-US/bundle/fastiron-09010-managementguide/page/GUID-CD3FD835-B641-45A4-8859-062E4AEABE75.html" target="_blank" rel="noopener"&gt;online documentation&lt;/A&gt; for more&amp;nbsp;troubleshooting steps on ICX-to-SZ onboarding.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Apr 2023 15:59:48 GMT</pubDate>
    <dc:creator>Orlando_Elias</dc:creator>
    <dc:date>2023-04-04T15:59:48Z</dc:date>
    <item>
      <title>Onboarding ICX switch to SZ/vSZ with Error: HTTP Response Code 400</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Onboarding-ICX-switch-to-SZ-vSZ-with-Error-HTTP-Response-Code/m-p/54777#M99</link>
      <description>&lt;P&gt;Are you having trouble to onboard an ICX switch into your SmartZone controller?&lt;/P&gt;
&lt;P&gt;Check the logs in the ICX switch with the command 'show log', if you see errors like these below, it's very likely there's a certificate issue between the ICX and the controller:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Jun 24 18:32:02:I:MGMT Agent: Failed to connect to network controller at 192.168.169.220 Error: HTTPS Connection Error&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Jun 24 18:31:42:I:MGMT Agent: Failed to connect to network controller at 192.168.169.220 Error: JSON Parse Error&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Jun 24 18:31:42:I:MGMT Agent: Failed to connect to network controller at 192.168.169.220 Error: HTTP Response Code 400&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;This error is common when working with 'non-TPM' switches, which means the switch uses &lt;STRONG&gt;self-signed certificates&lt;/STRONG&gt;. Switch models with this charatieristic are&amp;nbsp;&lt;SPAN&gt;ICX 7250, ICX 7450, or ICX 7750. Check your switch's certificate using the CLI comand 'dm verify-device-certs' as shown below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;SSH@ICX-7450#dm verify-device-certs&lt;BR /&gt;Commencing sanity check for device certs ...&lt;BR /&gt;Verifying files on Non-TPM Platform ...&lt;BR /&gt;Successfully verified&lt;BR /&gt;The device key pair is valid&lt;BR /&gt;The Encrypt/Decrypt test is successful&lt;BR /&gt;Successfully verified device certs&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;How to resolve this? There is a CLI command that you can run in SZ/vSZ to honor this kind of self-signed certificates of non-TPM switches.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;1. Log into the CLI of your controller using SSH and run the following commands.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ# config&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ(config)# non-tpm-switch-cert-validate&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Successful operation&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ(config)# exit&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;1-vSZ#&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;2. Your switch should now be onboarded.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Visit RUCKUS &lt;A href="https://docs.commscope.com/en-US/bundle/sz-600-cliguide-sz300/page/GUID-8B740B78-C390-4B7B-A271-6A511179B68A.html" target="_blank" rel="noopener"&gt;online documentation&lt;/A&gt; for more information about this CLI command.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;If the switch's certificate is corrupted or not valid, regenerate the certificates using the below two steps (this is only for non-TPM devices):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;a) Zeroize the current keys&lt;/SPAN&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; ICX(config)# crypto device-key-zeroize&lt;BR /&gt;&amp;nbsp; &amp;nbsp; ICX(config)# crypto device-cert-zeroize&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;SPAN&gt;b) Reload the ICX device&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;For TPM devices, we cannot regenerate a new cert through CLI, so you need to RMA the device if the certificate is corrupted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;Visit RUCKUS &lt;A href="https://docs.commscope.com/en-US/bundle/fastiron-09010-managementguide/page/GUID-CD3FD835-B641-45A4-8859-062E4AEABE75.html" target="_blank" rel="noopener"&gt;online documentation&lt;/A&gt; for more&amp;nbsp;troubleshooting steps on ICX-to-SZ onboarding.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 15:59:48 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/Onboarding-ICX-switch-to-SZ-vSZ-with-Error-HTTP-Response-Code/m-p/54777#M99</guid>
      <dc:creator>Orlando_Elias</dc:creator>
      <dc:date>2023-04-04T15:59:48Z</dc:date>
    </item>
  </channel>
</rss>

