This command enables or disables the provisioning of the LSCs on the APs if the APs just joined using
the SSC/MIC. If enabled, all APs that join and do not have the LSC will get provisioned.
If disabled, no more automatic provisioning will be done. This command does not affect the APs, which
already have LSCs in them.
•
config certificate lsc ra-cert
{
add
|
delete
}
We recommend this command when the CA server is a Cisco IOS CA server. The controller can use
the RA to encrypt the certificate requests and make communication more secure. RA certificates are not
currently supported by other external CA servers, such as MSFT.
◦
add
—Queries the configured CA server for an RA certificate using the SCEP operation and installs
it into the controller database. This keyword is used to get the certReq signed by the CA.
◦
delete
—Deletes the LSC RA certificate from the WLC database.
•
config auth-list ap-policy lsc
{
enable
|
disable
}
After getting the LSC, an AP tries to join the controller. Before the AP tries to join the controller, you
must mandatorily enter this command on the controller console. By default, the
config auth-list ap-policy
lsc
command is in the disabled state, and the APs are not allowed to join the controller using the LSC.
•
config auth-list ap-policy mic
{
enable
|
disable
}
After getting the MIC, an AP tries to join the controller. Before the AP tries to join the controller, you
must mandatorily enter this command on the controller console. By default, the
config auth-list ap-policy
mic
command is in the enabled state. If an AP cannot join because of the enabled state, this log message
on the controller side is displayed: LSC/MIC AP is not allowed to join.
•
show certificate lsc summary
This command displays the LSC certificates installed on the WLC. It would be the CA certificate, device
certificate, and optionally, an RA certificate if the RA certificate has also been installed. It also indicates
if an LSC is enabled or not.
•
show certificate lsc ap-provision
This command displays the status of the provisioning of the AP, whether it is enabled or disabled, and
whether a provision list is present or not.
•
show certificate lsc ap-provision details
This command displays the list of MAC addresses present in the AP provisioning lists.
Cisco Mesh Access Points, Design and Deployment Guide, Release 7.3
190
OL-27593-01
Connecting the Cisco 1500 Series Mesh Access Points to the Network
Locally Significant Certificates for Mesh APs