I've had a few APs go into dirty config after upgrading to AOS 6.4.x from 6.3.x. OPened a TAC case and never could get them out of dirty config when pointed them to a the upgraded 6.4 controller. These were remote APs in standard campus mode. Funning thing was the APs worked fine if I pointed them to another 6.3 controller or a different 6.4 controller. Was very strang.
In the end TAC recommended I convert them to RAP mode. Was very simple controller config but had to have someone console into the APs. TAC recommends and remote APs to a controller be in RAP mode so they use IPSEC instead of GRE as the MTU is handled differently. In any event I still use CAP in most remote sites but when I see dirty config converting to RAPs has been doing the trick.
May not apply in your case just thought I would mention in case it helps.