Meraki Authentication Server Certificate Rotation - July 2026
Click 日本語 for Japanese
Overview
As part of a standard yearly server certificate rotation to maintain Meraki Cloud Radius authentication security, Meraki rotates the RADIUS server certificate used for Meraki Cloud Authentication. The certificate in question is called Cisco Meraki Radius 2026 with the common name radius.meraki.com. Clients must trust this certificate for Meraki Cloud Authentication. The following is the expected impact and remediation steps of this yearly rotation.
The common name of the certificate will remain radius.meraki.com between rotations. If clients can remain trusting this service certificate common name there should be no impact from this certificate transition.
Recommended Remediation Actions for Various Deployment Scenarios
Meraki Authentication with Sentry Wi-Fi
Devices with Meraki Authentication with Systems Manager Sentry Wi-Fi that were online sometime after July 1, 2026 and before July 22, 2026, 01:30 UTC will have no impact.
For users with devices that were not online during this period, such devices will need to associate with an SSID which will allow them to check in with the dashboard for long enough to allow a check-in cycle to complete (~2 minutes) and receive the updated payload, and resume normal operation. Users can verify the payload is working by attempting to connect to the original Meraki Sentry Wi-Fi enabled SSID.

Note: Windows 10 and 11 users may need to select the appropriate certificate during the rotation process. Select the appropriate "SCEP Wi-Fi Certificate for {device_id}" and click OK.
![]()
Meraki Authentication without Sentry Wi-Fi
Users of Meraki Authentication via certificate-based authentication without Sentry Wi-Fi will need to 'trust' the new certificate with the below information upon associating to the Meraki Authentication SSID.
Host: radius.meraki.com
Issued: [TBD fill in when issued July 1, 2026]
Expires: [TBD Jan, 2027 GMT, fill in when issued]

Note: Some devices may require the SSID to be "forgotten" before they will be prompted to accept the new certificate.
Note: See the Meraki Authentication Radius Certificate below for the new certificate.
Trusted Access
Users of a Trusted Access configuration to an SSID will need to re-download their device's Trusted Access configuration from portal.meraki.com on or after the rotation date.
FAQs
1. What is changing?
Due to an approaching certificate expiration, Meraki will be rotating the RADIUS certificate for Meraki Cloud Authentication on July 22, 2026. This rotation is a standard yearly action taken to maintain Meraki Authentication security.
In some Systems Manager (SM) deployments, devices will automatically receive the new certificate and no further action will likely be required. However, there are certain deployment scenarios that may require action to be taken.
2. How can an affected network be identified?
Any services relying on Meraki Cloud Authentication via certificates will be affected. This includes Sentry Wi-Fi, Trusted Access Wi-Fi, and any manual authentication relying on Meraki Cloud Authentication via certificates.
3. Which network deployment scenarios require action to be taken?
Only SSIDs with Meraki Cloud Authentication using the RADIUS certificate for authentication will be affected.
If you are using this certificate for Meraki Cloud Authentication and have a network with any of the following deployment scenarios, your action may be required to manually accept the new certificate:
-
If you have non-Systems Manager (SM) deployment networks
-
If you utilize Meraki Authentication with Sentry Wi-Fi, but had devices offline before the rotation date
-
If you utilize a Trusted Access configuration to an SSID
Please refer to our documentation (above) for further network identification details and next steps.
4. Is there an action needed to maintain connectivity?
If your network is affected, you need to accept the new certificate for your devices before July 22, 2026, 01:30 UTC to maintain connectivity. Please refer to our documentation above for more information.
5. What happens if no action is taken by the certificate rotation date?
If devices are still using the outdated RADIUS certificate after July 22, 2026, they will not be able to connect back to the Meraki Cloud Authentication SSID until the new certificate is accepted. Please see our documentation (above) for more details and a list of recommended actions for avoiding impact on device connectivity.
6. Will this affect username or password authentication with Meraki Authentication?
If you are using Meraki Cloud Authentication with username/ password authentication (such as PEAP) will be prompted to 'trust' the new radius.meraki.com server certificate after the rotation date.
If you are using certificate-based authentication (such as EAP-TLS) where this RADIUS Meraki Cloud Authentication certificate is used, you will need to accept the new certificate before July 22, 2026, 01:30 UTC.
7. Where can I go if I need additional assistance?
If you have additional questions or need assistance, please contact Meraki Technical Support.
Open a case via:
-
Call your localized support line, which can be found at the bottom of the Meraki Technical Support webpage.
Certificate Details
The certificate below is the new radius.meraki.com server certificate that will be presented after the rotation. Administrators who manually manage RADIUS/EAP certificate trust should ensure the DigiCert Global Root G2 root CA and DigiCert Global G2 TLS RSA SHA256 2020 CA1 intermediate CA are trusted. The server certificate details and fingerprints are provided for verification.
Below is a copy of the certificate which users will be required to accept, as well as the plaintext output from reading the certificate with openssl:
CN: radius.meraki.com Issuer: DigiCert Global G2 TLS RSA SHA256 2020 CA1 Valid From: Jul 1 00:00:00 2026 GMT Valid To: Jan 15 23:59:59 2027 GMT SHA-256 Fingerprint: 10:7A:71:E3:75:A8:5D:6D:56:36:9A:F1:4B:33:23:FC:C6:D9:80:77:5F:8C:56:DB:EE:34:10:99:6F:CD:1B:97 SHA-1 Fingerprint: D7:C6:6C:3A:35:7F:4A:21:F9:21:1F:B0:ED:85:5F:AC:EB:3A:7F:59 Extended Key Usage: TLS Web Server Authentication
#Meraki Authentication Radius
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
07:53:56:f9:1a:69:7c:8d:ac:d5:a0:68:c5:1d:b1:ff
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
Validity
Not Before: Jul 1 00:00:00 2026 GMT
Not After : Jan 15 23:59:59 2027 GMT
Subject: C=US, ST=California, L=San Francisco, O=Meraki LLC, CN=radius.meraki.com
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (4096 bit)
Modulus:
00:e5:0e:bf:8b:8b:32:cb:59:bd:4b:22:91:5f:c2:
1b:65:b0:e1:c4:b3:b1:e3:c3:ac:13:c5:6c:b0:ed:
fe:c0:d7:7e:6e:be:fb:f9:01:dd:98:9e:58:9f:3b:
52:47:32:d7:6f:61:ce:25:64:95:a6:52:75:92:41:
f3:c2:e7:8f:90:f0:98:8f:08:5b:ef:79:6d:56:45:
c6:3b:9d:0b:9d:06:79:99:f2:1c:de:63:77:1a:a9:
4d:0d:82:c2:f9:b3:e6:52:99:9d:c7:ab:63:de:0d:
86:2b:39:09:bf:69:fe:49:c1:55:e5:a4:4b:6e:ba:
9e:c9:c5:c2:d7:15:66:65:91:33:ac:7a:24:ef:6e:
b5:a5:36:2e:43:b5:5e:e8:a5:01:7a:2f:6f:04:dd:
2c:81:29:36:88:51:b5:58:91:62:87:02:11:68:d2:
b2:e0:7d:ec:c0:54:77:3d:2d:02:77:e0:52:6a:07:
c5:08:bd:9d:cd:94:05:b5:d4:fa:9a:cf:86:9c:31:
6c:ca:0d:e7:d0:9d:82:33:24:ca:66:59:18:d4:fe:
a7:e3:51:9f:a4:b3:67:8c:d5:26:be:f3:bc:78:11:
d2:98:e1:1e:01:1c:78:2d:15:5c:ba:56:9a:17:d4:
a2:04:2b:c5:1e:80:8a:d1:0a:e5:c5:ff:7e:eb:cb:
56:13:8b:77:bc:f3:34:7c:b2:db:97:5f:bb:95:52:
75:bf:39:3b:1d:3b:79:7b:9d:31:b4:d3:ea:48:65:
be:05:ad:3b:52:2d:c5:30:d0:f5:e5:aa:b0:a2:0f:
e3:a4:ea:6c:41:45:57:78:df:23:ba:a1:cf:29:83:
8c:ca:0b:aa:b5:91:ca:b1:48:e5:0b:5c:e7:ed:63:
b2:ce:78:0e:78:b3:41:e0:e1:a1:42:e1:65:94:98:
ae:fb:5c:39:72:8f:c0:df:9d:91:93:b9:30:b2:b2:
f7:fa:c5:7e:fc:d7:3b:4e:fd:b8:42:a1:19:3f:98:
53:c3:05:e3:a8:83:50:1c:51:eb:5a:3e:61:2b:cc:
0c:88:8a:5a:91:20:94:f7:5d:85:b1:4d:5f:2d:da:
05:45:3f:e9:0b:ea:c1:84:91:7e:57:35:61:60:6e:
ae:4f:8c:8a:dd:54:f0:27:77:c9:bb:14:76:46:00:
ce:97:2e:23:b1:d6:72:35:92:6a:d3:34:57:14:3c:
92:7b:cb:92:94:1d:c0:f1:25:ee:ab:06:01:cf:a1:
c6:72:e1:3e:62:bc:e3:72:ed:01:4e:1c:a5:37:9e:
25:12:ee:a5:ab:1d:3c:17:fa:6a:a6:4c:6f:a4:32:
39:c4:bf:94:29:f3:20:06:06:d5:21:95:f2:80:14:
c7:1c:b1
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
74:85:80:C0:66:C7:DF:37:DE:CF:BD:29:37:AA:03:1D:BE:ED:CD:17
X509v3 Subject Key Identifier:
6F:FA:B3:B4:E8:6A:BE:D7:6A:6C:E6:23:87:D2:A4:39:87:41:33:2B
X509v3 Subject Alternative Name:
DNS:radius.meraki.com
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.2
CPS: http://www.digicert.com/CPS
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl3.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl
Full Name:
URI:http://crl4.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl
Authority Information Access:
OCSP - URI:http://ocsp.digicert.com
CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt
X509v3 Basic Constraints: critical
CA:FALSE
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 4C:63:DC:98:E5:9C:1D:AB:88:F6:1E:8A:3D:DE:AE:8F:
AB:44:A3:37:7B:5F:9B:94:C3:FB:A1:9C:FC:C1:BE:26
Timestamp : Jul 1 17:17:29.913 2026 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:FB:C1:F0:1A:DE:6E:DE:B1:8A:13:95:
B9:10:E1:FC:6B:87:03:AA:0B:D9:13:41:DE:65:50:3C:
79:49:8B:AD:E0:02:21:00:EE:72:A3:7B:DE:3C:17:04:
20:9E:A7:1E:B0:B9:02:E1:3F:98:F3:1F:1F:82:FA:E2:
D6:D3:3E:5E:44:DA:C4:60
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : D6:D5:8D:A9:D0:17:53:F3:6A:4A:A0:C7:57:49:02:AF:
EB:C7:DC:2C:D3:8C:D9:F7:64:C8:0C:89:19:1E:9F:02
Timestamp : Jul 1 17:17:29.889 2026 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:14:78:96:8D:FD:A1:CC:13:2F:73:2C:26:
3B:34:0F:0B:EF:96:CB:B4:F2:7B:86:FC:61:2D:C6:4F:
91:C6:0D:22:02:20:14:38:90:F5:13:E0:1F:68:83:C3:
FB:0D:3A:0F:DF:6F:6C:C5:37:4C:E2:2F:B0:7B:B4:EA:
BA:99:18:6A:8E:94
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 44:C2:BD:0C:E9:14:0E:64:A5:C9:4A:01:93:0A:5A:A1:
BB:35:97:0E:00:EE:11:16:89:68:2A:1C:44:D7:B5:66
Timestamp : Jul 1 17:17:29.947 2026 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:54:00:E6:31:DD:19:15:CD:EF:B6:FF:BF:
87:98:25:E4:1C:E8:9F:AC:A3:7B:A9:FA:C8:31:63:52:
AB:7A:F1:BD:02:20:26:76:81:F1:82:4E:BB:30:4A:F5:
35:34:93:E7:82:2C:41:52:29:BA:F9:F4:CB:9C:6B:F4:
61:A1:67:3D:C2:19
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
2a:c9:33:14:f0:9c:6c:5b:e1:b8:9c:30:27:c0:80:fd:74:1f:
a0:c2:26:76:d2:48:0c:28:14:30:cf:06:3f:e6:73:78:7f:29:
3a:71:86:cf:fc:c7:2f:4c:1c:48:a8:bf:41:70:e4:f9:e4:4d:
6b:0f:55:ae:95:cc:d1:e5:10:83:ca:8a:1f:b0:e8:de:f6:49:
e4:31:a6:d8:4c:9e:c1:c0:03:90:41:0b:7a:7a:9f:82:69:ee:
b6:27:19:ce:1e:31:e7:6e:68:5f:43:39:29:8f:62:04:e9:4d:
0d:41:2e:39:c8:02:97:38:09:eb:7f:fe:63:7c:aa:ab:1f:d1:
bd:8e:b3:72:da:65:08:d1:87:e3:cf:d4:41:d1:01:06:3d:62:
c8:59:dc:85:5e:54:69:fc:c7:5e:21:8a:e3:ff:8d:2d:97:62:
b3:f8:90:1c:67:57:f3:f5:d3:06:c0:30:c5:c8:65:ae:a5:41:
ba:69:15:c9:b2:e5:e2:86:80:4b:e8:62:d9:d6:16:c8:4c:78:
50:58:1c:05:2d:21:e5:29:34:f9:65:cc:5b:be:8d:15:ed:b8:
ff:e3:85:ef:cf:be:31:85:76:7f:08:a1:ae:62:59:f9:69:67:
b2:43:c7:91:18:ba:e1:b7:19:0c:67:86:1b:3a:77:f8:14:26:
d1:95:55:e3
sha256 Fingerprint=10:7A:71:E3:75:A8:5D:6D:56:36:9A:F1:4B:33:23:FC:C6:D9:80:77:5F:8C:56:DB:EE:34:10:99:6F:CD:1B:97
sha1 Fingerprint=D7:C6:6C:3A:35:7F:4A:21:F9:21:1F:B0:ED:85:5F:AC:EB:3A:7F:59

