Explains AP certificate renewal with LSC, describing benefits, prerequisites, restrictions, and procedures for configuring automatic and forced renewal through GUI and CLI, including verification steps.
AP certificate renewal (LSC)
AP certificate renewal (LSC) is a feature that
-
allows the renewal of Locally Significant Certificates (LSCs) for Access Points before their expiration
-
ensures that the APs can continue to provide seamless services by renewing their certificates in a timely manner
-
enables the controller to orchestrate this process to minimize service disruption. The process focuses on automatic renewal mechanisms that do not require manual intervention.
LSC provisioning and renewal methods
From Cisco IOS XE 26.2.1, supported access points can provision and renew LSC through either controller-based proxy enrollment or Cisco Catalyst Center secure AP onboarding. These certificates are crucial for your Access Points because they authenticate network communications. This renewal process is essential. Without a valid certificate, Access Points may lose network connectivity and affect network services.
The controller uses these methods to renew certificates:
-
Gradual Succession: A method where Access Points are renewed one at a time, which is suitable when the number of Access Points that are due for renewal is under a certain threshold.
-
Staggered Rollover: Access Points are renewed in a staggered fashion, minimizing the impact on radio coverage when the number of Access Points is larger.
-
One-Shot Renewal: All affected Access Points are renewed simultaneously, which can be disruptive and should be used as a last resort.
Benefits of AP certificate renewal (LSC)
-
Automated Renewal Process: Reduces the need for manual certificate updates, ensuring continuous service.
-
Seamless Network Operations: Minimizes network downtime by renewing certificates before they expire.
-
Enhanced Security: Maintains a high level of security by ensuring that all Access Points have valid certificates.
-
Scalable Management: Supports staggered AP renewal to reduce impact on network operations.
Requirements for AP certificate renewal (LSC)
Configure the controller and access points to use locally significant certificates before you proceed with certificate renewal.
-
Provision or renew the locally significant certificates through either the controller-based proxy-enrollment workflow or the Cisco Catalyst Center secure AP onboarding workflow.
-
Define the maintenance windows if scheduling is required for renewal.
Restrictions for AP certificate renewal (LSC)
-
Only one Local Significant Certificate is supported per access point.
-
Enable either staggered or one-shot renewal, not both.
-
Local Significant Certificate renewal applies to Cisco Wave 2 access points and newer models; older access points do not support this feature.
-
The staggered algorithm does not apply to access points in bridge mode. All Local Significant Certificate renewals for bridge mode access points occur at the same time.
Configure AP certificate auto-renewal (LSC) (GUI)
Follow these steps to configure AP certificate auto-renewal (LSC):
Procedure
Configure AP certificate renewal (LSC) (CLI)
Follow these steps to configure AP certificate renewal (LSC) in the controller:
Procedure
You have successfully configured AP certificate renewal (LSC).
Configure forced renewal of AP certificate (LSC) for individual or multiple APs (GUI)
Follow these steps to configure forced renewal of AP certificate (LSC) for individual or multiple APs via GUI:
Procedure
-
Choose Configuration > Wireless > Bulk AP Provisioning.
-
On the Select Parameters page, check the Renew LSC check box to renew the LSC for all selected APs.
-
Click Next.
Configure forced renewal of AP Certificate (LSC) based on site tag (GUI)
Before you begin
Follow these steps to configure force renewal of AP certificate (LSC) based on site tag:
Procedure
Configure forced renewal of AP Certificate (LSC) based on site tag (CLI)
Follow these steps to configure the forced renewal of an AP certificate (LSC) based on a site tag using the CLI:
Procedure
The configuration of the forced renewal of an AP Certificate (LSC) based on a site tag is complete.
Configure forced renewal of all APs (GUI)
Follow these steps to configure forced renewal of all APs (GUI):
Procedure
Verify AP certificate renewal (LSC)
Verify LSC configuration
To verify LSC provision-related configuration details for an AP, use this command:
Device# show ap lsc-provision info
AP name Ethernet MAC Radio MAC LSC authentication LSC workflow Cert expiry Last renew attempt Last renew failure
=========================================================================================================================================
AP-abc 1111.2222.3333 aaaa.bbbb.ccc0 Port-802.1x PNP Onboarding <time-stamp> <time-stamp>/NA reason-code
AP-123 1234.5678.9012 dddd.eeee.fff0 DTLS SCEP proxy <time-stamp> <time-stamp>/NA reason-code
AP-xyz 1010.1010.1010 abcd.efab.cde0 DTLS, Port-802.1x SCEP proxy <time-stamp> <time-stamp>/NA reason-code 0.0.0.0 372 64 AGL Enabled
Verify staggered LSC renewal upgrade configuration
To verify progress and status of staggered LSC renewal upgrade, use this command:
Device# show ap upgrade
Status: In progress
From version:
To version: Unknown
Started at: 10/23/2025 08:16:01 IST
Configured percentage: 15
Percentage complete: 0
Expected time of completion: 10/23/2025 08:24:01 IST
Client steering: Enabled
Client de-authentication: Enabled
Accounting percentage: 90%
Iteration expiry time: 15 minutes
Progress Report
---------------
Iterations
----------
Iteration Start time End time AP count
------------------------------------------------------------------------------------------------
0 10/23/2025 08:16:01 IST 10/23/2025 08:16:01 IST 0
1 10/23/2025 08:16:01 IST 10/23/2025 08:18:05 IST 1
2 10/23/2025 08:18:05 IST ONGOING 0
Upgraded
--------
Number of APs: 0
AP Name Radio MAC Iteration Status Site
----------------------------------------------------------------------------------------------------
In Progress
-----------
Number of APs: 1
AP Name Radio MAC
-------------------------------------------------
1815W 00be.7517.d980
Remaining
---------
Number of APs: 6
AP Name Radio MAC
-------------------------------------------------
9166-1 10f9.20fd.5400
non-9120-1 488b.0a47.d8c0
9136_1 687d.b45f.1610
9120-Dev a00f.3704.f3a0
9162-antenna ecf4.0c0e.9920
9176+alpine ecf4.0c92.bac0
APs not handled by Rolling AP Upgrade
-------------------------------------
AP Name Radio MAC Status Reason for not handling by Rolling AP Upgrade
----------------------------------------------------------------------------------------------------------------------