Latest Cisco, PMP, AWS, CompTIA, Microsoft Materials on SALE Get Now
C9800 WLC PKI Cert Renew Error
5228

SPOTO Cisco Expert

SPOTO Cisco Expert

Settle a problem:66

Answered:

As a Cisco technical engineer, I often see recurring issues pop up in community forums that can cause confusion for network administrators. One such log message that has been appearing on Catalyst 9800 Wireless LAN Controllers (WLCs) is the PKI certificate renewal failure for a specific trustpoint: sdn-network-infra-iwan.

If you see this error, don’t panic. While it looks alarming, it typically does not impact your wireless client connectivity or the overall stability of your network. Let’s break down what this error means and the simple, non-disruptive solution to fix it.

The Error Message

You may see the following log message periodically on your Catalyst 9800 WLC:

%PKI-2-CERT_RENEW_FAIL: Certificate renewal failed for trustpoint sdn-network-infra-iwan Reason : Failed to get ID certificate from CA server

This message indicates that the WLC is unable to automatically renew a specific certificate. The key to understanding this error is the trustpoint name: sdn-network-infra-iwan.

This is not a user-created trustpoint for services like 802.1x or the WLC’s web management GUI. Instead, this trustpoint and its associated certificate are automatically generated and managed by Cisco DNA Center (now Catalyst Center). It is used to establish a secure TLS connection for telemetry data between the WLC and DNA Center. The DNA Center itself acts as the Certificate Authority (CA) for this certificate, identified as cn=sdn-network-infra-ca.

The failure typically occurs when the automated renewal process between the WLC and DNA Center fails, often due to a state mismatch that can occur after a DNA Center upgrade or other maintenance activity.

Verifying the Issue

Before applying the fix, you can confirm the state of the certificate on your WLC using a few simple CLI commands.

1. Check the Trustpoint Status

This command will show you the last enrollment status.

show crypto pki trustpoint sdn-network-infra-iwan status

In a problem state, the output will likely show Last enrollment status: Failed.

wlc-a#show crypto pki trustpoint sdn-network-infra-iwan status
Trustpoint sdn-network-infra-iwan:
  Issuing CA certificate configured:
    ...
  Router General Purpose certificate configured:
    ...
  Last enrollment status: Failed
  Next enrollment attempt:
    10:25:08 UTC May 16 2024 
    * A new key will be generated *
    * Configuration will not be saved after enrollment *
  State:
    Keys generated ............. Yes (General Purpose, non-exportable)
    Issuing CA authenticated ....... Yes
    Certificate request(s) ..... Yes

2. Inspect the Certificate Details

This command gives you a detailed view of the certificate, including its validity dates. You’ll likely notice the end date or renew date is approaching.

show crypto pki certificates verbose sdn-network-infra-iwan

The output will show the certificate details, including the Issuer (sdn-network-infra-ca) and Subject, along with the validity period.

Certificate
  Status: Available
  ...
  Issuer: 
    cn=sdn-network-infra-ca
  Subject:
    Name: wlc-a.eu-central-1.compute.internal
    cn=C9800-CL-K9_9B1KVTSUSVQ_sdn-network-infra-iwan
    ...
  Validity Date: 
    start date: 10:24:16 UTC Jul 26 2023
    end   date: 10:24:16 UTC Jul 25 2024
    renew date: 10:25:08 UTC May 16 2024
  ...
  Associated Trustpoints: sdn-network-infra-iwan 

The Solution: Forcing a Telemetry Configuration Push from DNA Center

The solution does not involve running complex CLI commands on the WLC. Instead, you need to trigger a refresh of the telemetry configuration from the DNA Center GUI. This forces DNA Center to re-provision the connection and issue a new certificate to the WLC.

This procedure is non-disruptive to your wireless services and can be performed during production hours without impacting end-users.

Step-by-Step Guide:

  1. Log in to your Cisco DNA Center dashboard.
  2. Navigate to the Inventory page (Menu > Provision > Inventory).
  3. Find and select the WLC (or other affected device, as this can also occur on Catalyst 9K switches) that is reporting the error.
  4. Click the Actions button.
  5. In the Actions menu, navigate to Telemetry and select Update Telemetry Settings.
  6. In the dialog box that appears, you will see the current telemetry settings. Crucially, check the box for “Force Config Push”.
  7. Click Next and then Apply to push the configuration to the device.

(Image for illustrative purposes)

This process will force DNA Center to regenerate and push a new certificate to the WLC, resolving the renewal failure.

Post-Fix Verification

After applying the fix, you can run the same verification commands on the WLC’s CLI.

  1. Run show crypto pki trustpoint sdn-network-infra-iwan status. The output should now show Last enrollment status: Succeeded.
  2. Run show crypto pki certificates verbose sdn-network-infra-iwan. You will see that the certificate has a new serial number and new validity dates, confirming it has been successfully renewed.

Conclusion

The %PKI-2-CERT_RENEW_FAIL error for the sdn-network-infra-iwan trustpoint is a common, but easily resolved, issue for DNA Center-managed Catalyst 9800 WLCs. It relates directly to the management and telemetry plane and is fixed by forcing a configuration refresh from the DNA Center GUI. By following the simple steps above, you can resolve the error and ensure your network monitoring and management connection remains healthy, all without impacting your users.

Don't Risk Your Certification Exam Success – Take Real Exam Questions
Pass the Exam on Your First Try? 100% Exam Pass Guarantee