<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radsec established but no certificate in Aerohive Migrated Content</title>
    <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/radsec-established-but-no-certificate/m-p/85394#M10667</link>
    <description>&lt;P&gt;Well, it didn't work in my case. Complete upload did not pull certs from IDM servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All APs are in the same subnet. 2 of them were automaticaly elected as ID Manager Proxy Server and they are fine. Rest of access points – some of them have Radsec certificate and some don’t.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I managed to fix it this way:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I applied network policy that contains IDManager settings only to 2 APs in subnet. They were automaticaly elected as Proxy Servers and downloaded certificate. Then I repeated that procedure for rest of APs. They all have now valid certificate.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disadvantage of this solution is completion time. It takes a lot of time if you have many APs on site.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Apr 2018 14:03:57 GMT</pubDate>
    <dc:creator>marek_szymonski</dc:creator>
    <dc:date>2018-04-12T14:03:57Z</dc:date>
    <item>
      <title>Radsec established but no certificate</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/radsec-established-but-no-certificate/m-p/85392#M10665</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm reffering to this topic in old HiveNation community (https://community.aerohive.com/aerohive/topics/radsec-established-but-no-certificate). There is a procedure described how to fix lack of certificate from Radsec on AP:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Clear the key&lt;/P&gt;&lt;P&gt;clear aaa radius-server-key radsec ca&lt;/P&gt;&lt;P&gt;clear aaa radius-server-key radsec root-ca&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Upload the new CA&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upload the new CA: Monitor &amp;gt; Actions &amp;gt; Download CA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Complete Upload&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) Reboot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using HM 6.8r7a and there is no Monitor &amp;gt; Actions &amp;gt; Download CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried Complete configuration update and Clear ID Manager credentials but no luck.&lt;/P&gt;&lt;P&gt;All required ports are opened and  problem is only on some APs 250&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#sh idm&lt;/P&gt;&lt;P&gt;IDM client: Enabled Per SSID&lt;/P&gt;&lt;P&gt;IDM Proxy IP: 10.66.164.36&lt;/P&gt;&lt;P&gt;IDM proxy: Disabled&lt;/P&gt;&lt;P&gt;RadSec Certificate state: Not exist&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advice how to get RadSec certificate.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 16:01:28 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/radsec-established-but-no-certificate/m-p/85392#M10665</guid>
      <dc:creator>marek_szymonski</dc:creator>
      <dc:date>2018-04-11T16:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Radsec established but no certificate</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/radsec-established-but-no-certificate/m-p/85393#M10666</link>
      <description>&lt;P&gt;I'm sorry for the confusion, those instructions are for HiveManager NG and it sounds like you are using HiveManager Classic. These are different platforms so they sometimes have different procedures. If you run those two commands in step one, go ahead and skip step two, and move directly to step three. The AP will pull the certs from the IDM servers automatically, so you should accomplish the same thing by just clearing the certs and pushing out a complete configuration (which requires a reboot). &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps. &lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 21:42:40 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/radsec-established-but-no-certificate/m-p/85393#M10666</guid>
      <dc:creator>samantha_lynn</dc:creator>
      <dc:date>2018-04-11T21:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Radsec established but no certificate</title>
      <link>https://community.extremenetworks.com/t5/aerohive-migrated-content/radsec-established-but-no-certificate/m-p/85394#M10667</link>
      <description>&lt;P&gt;Well, it didn't work in my case. Complete upload did not pull certs from IDM servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All APs are in the same subnet. 2 of them were automaticaly elected as ID Manager Proxy Server and they are fine. Rest of access points – some of them have Radsec certificate and some don’t.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I managed to fix it this way:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I applied network policy that contains IDManager settings only to 2 APs in subnet. They were automaticaly elected as Proxy Servers and downloaded certificate. Then I repeated that procedure for rest of APs. They all have now valid certificate.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disadvantage of this solution is completion time. It takes a lot of time if you have many APs on site.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 14:03:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/aerohive-migrated-content/radsec-established-but-no-certificate/m-p/85394#M10667</guid>
      <dc:creator>marek_szymonski</dc:creator>
      <dc:date>2018-04-12T14:03:57Z</dc:date>
    </item>
  </channel>
</rss>

