# Problem to put a Lets Encrypt certificate on WLC

**URL:** <https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829>\
**Category:** Help\
**Created:** [September 10, 2018, 3:30pm UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829 "2018-09-10T15:30:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sebasti1](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@sebasti1](https://community.letsencrypt.org/u/sebasti1)\
**Post date:** [September 10, 2018, 3:30pm UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829/1 "2018-09-10T15:30:31Z")

</div>

Hello,

I generated a certificate signed by Let’s Encrypt thanks to this site: [https://gethttpsforfree.com/](https://gethttpsforfree.com/)

I took the CSR of the WebAuth certificate from the WLC controller to be able to generate the signed certificate. Then I add the Root certificate that is on the site: [https://letsencrypt.org/certs/isrgrootx1.pem.txt](https://letsencrypt.org/certs/isrgrootx1.pem.txt)  
following the intermediate certificate. I have my final certificate which contains:

- signed certificate
- intermediate certificate
- Root certificate

Then I import the final certificate (final.pem) via the graphical interface of the WLC controller.  
the controller tells me that the certificate is not correct. It seems that the certificate signed by let’s Encrypt and the intermediate certificate is in SHA2 while the Root certificate is in SHA1. How can I get a Let’s Encrypt Root certificate in SHA2 please?

Thanks and regards.

Sébastien.

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [September 10, 2018, 3:34pm UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829/2 "2018-09-10T15:34:33Z")

</div>

Hi,

> [@sebasti1](#):
>
> SHA2

The cross signed certificate is signed by an SHA1 root..(Identrust). Hence even if you imported the SHA2 ISRG CA, it's not the correct chain of trust....

You should import the sha1 Identrust certificate, not the ISRG root CA to form a correct chain of trust.

Thank you

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [September 10, 2018, 3:35pm UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829/3 "2018-09-10T15:35:31Z")

</div>

Hi @sebasti1

> [@sebasti1](#):
>
> It seems that the certificate signed by let’s Encrypt and the intermediate certificate is in SHA2 while the Root certificate is in SHA1.

save the file in Windows

[https://letsencrypt.org/certs/isrgrootx1.pem.txt](https://letsencrypt.org/certs/isrgrootx1.pem.txt)

as isrg-root.crt, then you can open it. You see:

![ISRG-Root](https://global.discourse-cdn.com/letsencrypt/original/3X/7/a/7ad4366e1116b23a6167860cba4f222d8469074a.png)

It's with SHA256 signed.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [September 10, 2018, 5:55pm UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829/4 "2018-09-10T17:55:25Z")

</div>

SHA-1 root certificates aren’t a problem for anything, though. Root certificates are trusted because you trust them. The signature, and what algorithm it uses, aren’t important.

A lot of widely used roots are SHA-1.

---

<div class="post-metadata">

**Author:** ![jared.m](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jared.m/32/17871_2.png) [@jared.m](https://community.letsencrypt.org/u/jared.m)\
**Post date:** [September 10, 2018, 6:43pm UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829/5 "2018-09-10T18:43:40Z")

</div>

I don’t think you should include the root certificate in the chain anyway, just the leaf and intermediate.

---

<div class="post-metadata">

**Author:** ![sebasti1](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@sebasti1](https://community.letsencrypt.org/u/sebasti1)\
**Post date:** [September 11, 2018, 6:54am UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829/6 "2018-09-11T06:54:07Z")

</div>

Hello !

First of all, I thank you for your answers.

Concretely I would like to know how to integrate a certificate on my WLC controller? I managed to generate the signed and intermediate certificate thanks to the following link: [https://gethttpsforfree.com/](https://gethttpsforfree.com/) . What do I need to add to get my certificate to import on the controller please?

Thanks and regards.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 11, 2018, 7:11am UTC](https://community.letsencrypt.org/t/problem-to-put-a-lets-encrypt-certificate-on-wlc/71829/8 "2018-10-11T07:11:17Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
