Aruba Instant & Cloud Wi-Fi

Reply
Occasional Contributor I
Posts: 5
Registered: ‎09-03-2014

Error when uploading new cert

Hi there:

 

It took me a little bit, but I finally ran into the cert revokation issue. Here's where I'm at...

 

I cretaed my RSA key, and purchased a cert from Comodo. Blah, blah, received my public cert. I imported into trusted and intermediate. I then exported the public cert, the private key, and the intermediate cert. Then I copied those to my Mac, opened terminal, and ran the three cat commands (per this thread: https://community.arubanetworks.com/t5/Controller-less-WLANs/ArubaOS-Default-Certificate-Revocation-FAQ-Instant/ta-p/275814) without error to combine them into a pem cert. But when I try to upload to my T105 (6.4.2.6-x; won't go any higher), i get the error:

 

cert_upload_split_certificate_file_failed_head (see attached screen).

 

I suppose it could be a corrupted cert I received, but I got no errors on my CA when importing. Can anyone help me out here?

 

Thanks

Occasional Contributor I
Posts: 9
Registered: ‎11-30-2016

Re: Error when uploading new cert

I had the same issue with 205 AP when I tried to import our server pem file. CA worked first time.
I resolved it by exporting a pfx certificate from our IIS server and then importing the pfx choosing the pcks option on the drop down menu.
Keep in mind that there is a custom build firmware that bypass the revoked certificate without the need of a public one, give that a try before importing your certificate. If you import and assign your certificate then the workaround doesn't work anymore. Custom build firmware is 6.4.4.4-4.2.3.3_56794.
Also have a look at
https://community.arubanetworks.com/t5/Aruba-Instant-Cloud-Wi-Fi/How-can-i-upload-a-new-portal-certificate-in-Aruba-Central/td-p/277886
Occasional Contributor I
Posts: 5
Registered: ‎09-03-2014

Re: Error when uploading new cert

Thanks, Bourasp:

 

Just about 30 minutes ago, I was able to successfully configure and upload a good pem file. UNFORTUNATELY...

 

Now, while I can ping my APs, I have no access to the GUI

(This site can’t be reached. The connection was reset.)  But users seem to have connectivity, so, that's good.

 

Argh!

 

Well, I'm off for the weekend. I'll pick this up on Monday. Y'all have a good one.

Occasional Contributor I
Posts: 9
Registered: ‎11-30-2016

Re: Error when uploading new cert

Hi,
I think it's the certificate usage settings, If nothing else works check the thing with the new group etc. And then choose the certificate usage for captive only.
Occasional Contributor I
Posts: 5
Registered: ‎09-03-2014

Re: Error when uploading new cert

Man, I'm dead. Not sure how to upload a cert for captive if I can't log in. Plus, I need to get my hands on a 14 ft. ladder to get to them.

 

Argh!!

Guru Elite
Posts: 21,022
Registered: ‎03-29-2007

Re: Error when uploading new cert


shmengie wrote:

Man, I'm dead. Not sure how to upload a cert for captive if I can't log in. Plus, I need to get my hands on a 14 ft. ladder to get to them.

 

Argh!!


Maybe not.  What browser are you using?



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Occasional Contributor I
Posts: 9
Registered: ‎11-30-2016

Re: Error when uploading new cert

Hi,

Can you try using SSH to get to them?

Occasional Contributor I
Posts: 5
Registered: ‎09-03-2014

Re: Error when uploading new cert

Colin:

 

Yeah, I thought of that. I've tried Chrome, IE, Safari and Firefox. Just cannot get in. It wants to let me in; I've added the exception to Firefox, but then I get "Secure connection Failed." I've changed the cert in Safari to "Always Trust", and the page comes up blank.

 

At the end of the day, the users are not affected, I just can't manage my APs. So, not critical. YET. And, I can bounce them by power cycling the POE injectors in the server room, if I have to.

 

Thanks for the idea, though.

Occasional Contributor I
Posts: 5
Registered: ‎09-03-2014

Re: Error when uploading new cert

Good idea. But, no...cannot Putty in, either.

Search Airheads
Showing results for 
Search instead for 
Did you mean: