98| Contr ol Plane Security DellPowerConnect W- Series ArubaOS 6.2 | User Guide
approvedas a secure AP until a network administrator manuallychanges the status of the AP to verify that i t is
not compromised. If anA P is in this state due to connectivity problems, thent heAP recovers and is takeno ut
of this holds tate as soon as connectivity is restored.
lcertified-hold-switch-cert: An AP is put in this state when the controller thinks the AP has been certified with a
controllercertificate yet the AP requests to be certified again. Since this is not a normal condition, the AP is not
be approvedas a s ecureAP until a network administrator manuallychanges the status of the AP to verify that i t
is not compromised. If an AP is in this state due to connectivity problems, then theA P recoversand is taken out
of this holds tate as soon as connectivity is restored.
Verifying Certificates
If you are unableto configure the control planesecurity featureo n W-600 Series, W-3000 Series, W-6000M3, or W-
7200 Series Dell controllers, verify that its Trusted Platform Module(TPM) and facto ry-installedcertificates are
presentand valid by accessi ngt heco ntroller’scommand-line interface andi ssuing the command
show tpm cert-info.If the controller has a validcerti ficate, the output of the commandshould appear similar to
the output in the examplebelow.
If the controllerdisplays the following output, it may have a corrupted or missing TPM and factory certificates.
Contact Dell technical support.
Disabling Co ntrol Plane Se curity
If you disable control plane security on a standalone or local controller, allA Ps connected to that controller reboot
then reconnectt o the controller over a clear channel.
If your disable control plane security on a

master

controller,APs directly connected to the master controller reboot
then reconnectt o the master controller over a clear channel.However, its local D ellcontrollers continue to
communicate with their APs over a secure channeluntil you save yo urco nfigurationo n the master controller.Once
you save the configuration,t hechanges are pushed down to the local Dell controllers.At t hat point, any APs
connected to the local Dell controllers also reboot and reconnect over a secure channel.
Verifying Whitelist Syn chronization
To verify that a network of master and local Dell controllers are correctly sharing their campus AP whitelists, check
the sequencenumbers on the master and local switch whitelists.
lThe sequencenumber value on a master controller should be the same as the remote sequence number on the
localc ontroller.
lThe sequencenumber value on a local controller should be the same as the remote sequence numbero n the
master controller.