Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Controller self-signed certificates for wireless AP Join

Want to summarize with AI?

Log in

This topic explains controller self-signed certificates, which are digital certificates generated by a wireless controller to enable secure CAPWAP communication and facilitate access point (AP) onboarding when manufacturer-installed certificates are unavailable or incompatible.


A controller self-signed certificate is a digital certificate generated and issued by a wireless controller itself that

  • enables secure CAPWAP communication for access point (AP) join processes

  • is used when manufacturer installed SUDI certificates are unavailable or incompatible, and

  • helps ensure connectivity and secure onboarding of APs under specific scenarios.

Self-signed certificates allow Cisco Catalyst controllers to fulfill certificate requirements for AP joining and management, especially when manufacturer-installed or third-party certificates are missing or cannot be validated.

Requirement: Use minimum RSA key size for DTLS connections

Always ensure certificates used for DTLS connections (for AP and mobility) have an RSA key size of at least 2048 bits. Using a smaller key size will cause AP and mobility connections to fail after a reload.

This principle applies to all DTLS connections involving access points (AP) and mobility features that require device certificates.

Using a minimum RSA key size of 2048 bits ensures compliance with security best practices and prevents connection failures due to insufficient key strength.

DTLS connections for AP and mobility will remain operational after a reload when certificates meet the minimum RSA key size requirement.

To verify the device certificate key size, use this command:

show crypto pki certificate verbose tp-name

Replace tp-name with your trustpoint name.