03-02-2022 01:07 AM - edited 11-26-2024 03:33 PM
As a Sr. Technical Support Engineer, I have encountered the following concern/issue from many users and would like to share my experience here:
Root Cause:
Ruckus's original device certificates expired in November 2016. Any device manufactured before November 2016 has the old certificate.
How to find an AP certificate:
rkscli: get rpki-cert issuer
Issuer: Ruckus Wireless, Inc.
OK
Why do I see the warning "AP certificate is expired" on my controller dashboard?
vSZ/SZ versions prior to the 3.6.x firmware release do not have AP-cert check enabled by default. Therefore, the APs that joined the controller before 3.6.x and were later upgraded to 3.6.x or above will display the following error message/warning on the controller dashboard.
Export the All AP Certificate file from the controller (the below screenshot is from the older versions pre-5.x and 3.6.x): -
Here is a screenshot from the updated vSZ/SZ firmware version (above 3.6.x): -
It displays the page shown below:
4. This process will take some time, and the AP will refresh its certificates.
Solved! Go to Solution.
10-16-2023 03:03 AM
Hello @Marcel_Antony ,
Hope you doing well today.
We recommend upgrading the AP certificate. The APs with old certs won't join any vSZ/SZ/SmartZone controller/Cloud controller until you disable the AP-cert check on the controller.
If the APs are currently managed by the controller and are online and for some reason get disconnected and the AP entry is lost then the AP won't join back the controller.
Let me know if this answers your query.
Regards,
Sarita
10-11-2023 10:15 AM
Hello,
Can someone explain what will be the impact if the AP certificate has expired in several AP's?
Thank you
10-16-2023 03:03 AM
Hello @Marcel_Antony ,
Hope you doing well today.
We recommend upgrading the AP certificate. The APs with old certs won't join any vSZ/SZ/SmartZone controller/Cloud controller until you disable the AP-cert check on the controller.
If the APs are currently managed by the controller and are online and for some reason get disconnected and the AP entry is lost then the AP won't join back the controller.
Let me know if this answers your query.
Regards,
Sarita