Settle a problem:66
As a Cisco technical engineer, I often see recurring issues pop up in community forums that can cause confusion for network administrators. One such log message that has been appearing on Catalyst 9800 Wireless LAN Controllers (WLCs) is the PKI certificate renewal failure for a specific trustpoint: sdn-network-infra-iwan.
If you see this error, don’t panic. While it looks alarming, it typically does not impact your wireless client connectivity or the overall stability of your network. Let’s break down what this error means and the simple, non-disruptive solution to fix it.
You may see the following log message periodically on your Catalyst 9800 WLC:
%PKI-2-CERT_RENEW_FAIL: Certificate renewal failed for trustpoint sdn-network-infra-iwan Reason : Failed to get ID certificate from CA server
This message indicates that the WLC is unable to automatically renew a specific certificate. The key to understanding this error is the trustpoint name: sdn-network-infra-iwan.
This is not a user-created trustpoint for services like 802.1x or the WLC’s web management GUI. Instead, this trustpoint and its associated certificate are automatically generated and managed by Cisco DNA Center (now Catalyst Center). It is used to establish a secure TLS connection for telemetry data between the WLC and DNA Center. The DNA Center itself acts as the Certificate Authority (CA) for this certificate, identified as cn=sdn-network-infra-ca.
The failure typically occurs when the automated renewal process between the WLC and DNA Center fails, often due to a state mismatch that can occur after a DNA Center upgrade or other maintenance activity.
Before applying the fix, you can confirm the state of the certificate on your WLC using a few simple CLI commands.
1. Check the Trustpoint Status
This command will show you the last enrollment status.
show crypto pki trustpoint sdn-network-infra-iwan status
In a problem state, the output will likely show Last enrollment status: Failed.
wlc-a#show crypto pki trustpoint sdn-network-infra-iwan status
Trustpoint sdn-network-infra-iwan:
Issuing CA certificate configured:
...
Router General Purpose certificate configured:
...
Last enrollment status: Failed
Next enrollment attempt:
10:25:08 UTC May 16 2024
* A new key will be generated *
* Configuration will not be saved after enrollment *
State:
Keys generated ............. Yes (General Purpose, non-exportable)
Issuing CA authenticated ....... Yes
Certificate request(s) ..... Yes
2. Inspect the Certificate Details
This command gives you a detailed view of the certificate, including its validity dates. You’ll likely notice the end date or renew date is approaching.
show crypto pki certificates verbose sdn-network-infra-iwan
The output will show the certificate details, including the Issuer (sdn-network-infra-ca) and Subject, along with the validity period.
Certificate
Status: Available
...
Issuer:
cn=sdn-network-infra-ca
Subject:
Name: wlc-a.eu-central-1.compute.internal
cn=C9800-CL-K9_9B1KVTSUSVQ_sdn-network-infra-iwan
...
Validity Date:
start date: 10:24:16 UTC Jul 26 2023
end date: 10:24:16 UTC Jul 25 2024
renew date: 10:25:08 UTC May 16 2024
...
Associated Trustpoints: sdn-network-infra-iwan
The solution does not involve running complex CLI commands on the WLC. Instead, you need to trigger a refresh of the telemetry configuration from the DNA Center GUI. This forces DNA Center to re-provision the connection and issue a new certificate to the WLC.
This procedure is non-disruptive to your wireless services and can be performed during production hours without impacting end-users.
Step-by-Step Guide:
(Image for illustrative purposes)
This process will force DNA Center to regenerate and push a new certificate to the WLC, resolving the renewal failure.
After applying the fix, you can run the same verification commands on the WLC’s CLI.
show crypto pki trustpoint sdn-network-infra-iwan status. The output should now show Last enrollment status: Succeeded.show crypto pki certificates verbose sdn-network-infra-iwan. You will see that the certificate has a new serial number and new validity dates, confirming it has been successfully renewed.The %PKI-2-CERT_RENEW_FAIL error for the sdn-network-infra-iwan trustpoint is a common, but easily resolved, issue for DNA Center-managed Catalyst 9800 WLCs. It relates directly to the management and telemetry plane and is fixed by forcing a configuration refresh from the DNA Center GUI. By following the simple steps above, you can resolve the error and ensure your network monitoring and management connection remains healthy, all without impacting your users.