12 - 48 WiNG 5.6 Access Point System Reference Guide
Use the Crypto Certificate Renewal screen to view and if required, trigger certificate renewal for CMP certificates.
1. Refer to the following for more information on Crypto CMP Certificates:
2. Select Trigger Certificate Renewal to begin update the credentials of the certificate. If a renewal succeeds, the newly
obtained certificate overwrites an existing certificate. If the renewal fails, an error is logged.
3. Select Refresh to update the screen to the last saved configuration.
12.1.12 Re-elect Controller
Devices
Use the Controller Re-election screen to identity available access point resources within a selected RF Domain and
optionally make some, or all, of the access points available to initiate tunnel connections.
To re-elect controller adoption resources for tunnel establishment:
1. Select Operations.
2. Ensure a RF Domain is selected from the Operations menu on the top, left-hand, side of the screen. Otherwise, the Re-
elect Controller screen cannot be located, as it does not display at either the system or device levels of the hierarchal tree.
3. Select the Re-elect Controller tab.
Hostname Lists the administrator assigned hostname of the CMP resource requesting a certificate
renewal from the CMP CA server.
MAC Address Lists the hardware encoded MAC address of the CMP server resource.
Trust Point Name Lists the 32 character maximum name assigned to the target trustpoint. A trustpoint represents
a CA/identity pair containing the identity of the CA, CA specific configuration parameters, and
an association with an enrolled identity certificate.
Trust Point Valid
Until
The expiration of the CMP certificate is checked once a day. When a certificate is about to
expire a certificate renewal can initiated with the server via an existing IPsec tunnel. If the
tunnel is not established, the CMP renewal request is not sent.
NOTE: Take care when selecting access points for controller re-election, as client con-
nections may be broken on upon re-election. Ensure an elected access point's client load
can be compensated by another access point in the same RF Domain.
NOTE: The Re-elect Controller tab is only available at the RF Domain level of the UI’s
hierarchal tree and is not available for access points.