Skip to main content

 

Cisco Meraki Documentation

Meraki Authentication Server Certificate Rotation - July 2026

Click 日本語 for Japanese

Overview

As part of a standard yearly server certificate rotation to maintain Meraki Cloud Radius authentication security, Meraki rotates the RADIUS server certificate used for Meraki Cloud Authentication. The certificate in question is called Cisco Meraki Radius 2026 with the common name radius.meraki.com. Clients must trust this certificate for Meraki Cloud Authentication. The following is the expected impact and remediation steps of this yearly rotation. 

The common name of the certificate will remain radius.meraki.com between rotations. If clients can remain trusting this service certificate common name there should be no impact from this certificate transition. 

Recommended Remediation Actions for Various Deployment Scenarios


Meraki Authentication with Sentry Wi-Fi 

Devices with Meraki Authentication with Systems Manager Sentry Wi-Fi that were online sometime after July 1, 2026 and before July 22, 2026, 01:30 UTC will have no impact.  

For users with devices that were not online during this period, such devices will need to associate with an SSID which will allow them to check in with the dashboard for long enough to allow a check-in cycle to complete (~2 minutes) and receive the updated payload, and resume normal operation. Users can verify the payload is working by attempting to connect to the original Meraki Sentry Wi-Fi enabled SSID. 
Meraki_Auth_Server_Cert_Sentry_WiFi.png

Note: Windows 10 and 11 users may need to select the appropriate certificate during the rotation process. Select the appropriate "SCEP Wi-Fi Certificate for {device_id}" and click OK. 

wificonnect-windows.png

Meraki Authentication without Sentry Wi-Fi 

Users of Meraki Authentication via certificate-based authentication without Sentry Wi-Fi will need to 'trust' the new certificate with the below information upon associating to the Meraki Authentication SSID.  

Host: radius.meraki.com 
Issued: [TBD fill in when issued July 1, 2026]
Expires:  [TBD Jan, 2027  GMT, fill in when issued]
Meraki_Auth_Server_Cert_without_Sentry_WiFi.png

Note: Some devices may require the SSID to be "forgotten" before they will be prompted to accept the new certificate.

Note: See the Meraki Authentication Radius Certificate below for the new certificate. 

Trusted Access 

Users of a Trusted Access configuration to an SSID will need to re-download their device's Trusted Access configuration from portal.meraki.com on or after the rotation date. 

FAQs   

1. What is changing?

Due to an approaching certificate expiration, Meraki will be rotating the RADIUS certificate for Meraki Cloud Authentication on July 22, 2026. This rotation is a standard yearly action taken to maintain Meraki Authentication security.

In some Systems Manager (SM) deployments, devices will automatically receive the new certificate and no further action will likely be required. However, there are certain deployment scenarios that may require action to be taken.

2. How can an affected network be identified?

Any services relying on Meraki Cloud Authentication via certificates will be affected. This includes Sentry Wi-Fi, Trusted Access Wi-Fi, and any manual authentication relying on Meraki Cloud Authentication via certificates.   

3. Which network deployment scenarios require action to be taken?

Only SSIDs with Meraki Cloud Authentication using the RADIUS certificate for authentication will be affected.  

If you are using this certificate for Meraki Cloud Authentication and have a network with any of the following deployment scenarios, your action may be required to manually accept the new certificate: 

  • If you have non-Systems Manager (SM) deployment networks 

  • If you utilize Meraki Authentication with Sentry Wi-Fi, but had devices offline before the rotation date 

  • If you utilize a Trusted Access configuration to an SSID 

Please refer to our documentation (above) for further network identification details and next steps. 

4. Is there an action needed to maintain connectivity?

If your network is affected, you need to accept the new certificate for your devices before July 22, 2026, 01:30 UTC to maintain connectivity. Please refer to our documentation above for more information. 

5. What happens if no action is taken by the certificate rotation date?

If devices are still using the outdated RADIUS certificate after July 22, 2026, they will not be able to connect back to the Meraki Cloud Authentication SSID until the new certificate is accepted. Please see our documentation (above) for more details and a list of recommended actions for avoiding impact on device connectivity.  

6. Will this affect username or password authentication with Meraki Authentication?

If you are using Meraki Cloud Authentication with username/ password authentication (such as PEAP) will be prompted to 'trust' the new radius.meraki.com server certificate after the rotation date. 

If you are using certificate-based authentication (such as EAP-TLS) where this RADIUS Meraki Cloud Authentication certificate is used, you will need to accept the new certificate before July 22, 2026, 01:30 UTC. 

7. Where can I go if I need additional assistance?

If you have additional questions or need assistance, please contact Meraki Technical Support.  

Open a case via: 

Certificate Details 

The certificate below is the new radius.meraki.com server certificate that will be presented after the rotation. Administrators who manually manage RADIUS/EAP certificate trust should ensure the DigiCert Global Root G2 root CA and DigiCert Global G2 TLS RSA SHA256 2020 CA1 intermediate CA are trusted. The server certificate details and fingerprints are provided for verification.

Below is a copy of the certificate which users will be required to accept, as well as the plaintext output from reading the certificate with openssl:

CN: radius.meraki.com
Issuer: DigiCert Global G2 TLS RSA SHA256 2020 CA1
Valid From: Jul 1 00:00:00 2026 GMT
Valid To: Jan 15 23:59:59 2027 GMT
SHA-256 Fingerprint: 10:7A:71:E3:75:A8:5D:6D:56:36:9A:F1:4B:33:23:FC:C6:D9:80:77:5F:8C:56:DB:EE:34:10:99:6F:CD:1B:97
SHA-1 Fingerprint: D7:C6:6C:3A:35:7F:4A:21:F9:21:1F:B0:ED:85:5F:AC:EB:3A:7F:59
Extended Key Usage: TLS Web Server Authentication
#Meraki Authentication Radius 
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            07:53:56:f9:1a:69:7c:8d:ac:d5:a0:68:c5:1d:b1:ff
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1
        Validity
            Not Before: Jul  1 00:00:00 2026 GMT
            Not After : Jan 15 23:59:59 2027 GMT
        Subject: C=US, ST=California, L=San Francisco, O=Meraki LLC, CN=radius.meraki.com
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Modulus:
                    00:e5:0e:bf:8b:8b:32:cb:59:bd:4b:22:91:5f:c2:
                    1b:65:b0:e1:c4:b3:b1:e3:c3:ac:13:c5:6c:b0:ed:
                    fe:c0:d7:7e:6e:be:fb:f9:01:dd:98:9e:58:9f:3b:
                    52:47:32:d7:6f:61:ce:25:64:95:a6:52:75:92:41:
                    f3:c2:e7:8f:90:f0:98:8f:08:5b:ef:79:6d:56:45:
                    c6:3b:9d:0b:9d:06:79:99:f2:1c:de:63:77:1a:a9:
                    4d:0d:82:c2:f9:b3:e6:52:99:9d:c7:ab:63:de:0d:
                    86:2b:39:09:bf:69:fe:49:c1:55:e5:a4:4b:6e:ba:
                    9e:c9:c5:c2:d7:15:66:65:91:33:ac:7a:24:ef:6e:
                    b5:a5:36:2e:43:b5:5e:e8:a5:01:7a:2f:6f:04:dd:
                    2c:81:29:36:88:51:b5:58:91:62:87:02:11:68:d2:
                    b2:e0:7d:ec:c0:54:77:3d:2d:02:77:e0:52:6a:07:
                    c5:08:bd:9d:cd:94:05:b5:d4:fa:9a:cf:86:9c:31:
                    6c:ca:0d:e7:d0:9d:82:33:24:ca:66:59:18:d4:fe:
                    a7:e3:51:9f:a4:b3:67:8c:d5:26:be:f3:bc:78:11:
                    d2:98:e1:1e:01:1c:78:2d:15:5c:ba:56:9a:17:d4:
                    a2:04:2b:c5:1e:80:8a:d1:0a:e5:c5:ff:7e:eb:cb:
                    56:13:8b:77:bc:f3:34:7c:b2:db:97:5f:bb:95:52:
                    75:bf:39:3b:1d:3b:79:7b:9d:31:b4:d3:ea:48:65:
                    be:05:ad:3b:52:2d:c5:30:d0:f5:e5:aa:b0:a2:0f:
                    e3:a4:ea:6c:41:45:57:78:df:23:ba:a1:cf:29:83:
                    8c:ca:0b:aa:b5:91:ca:b1:48:e5:0b:5c:e7:ed:63:
                    b2:ce:78:0e:78:b3:41:e0:e1:a1:42:e1:65:94:98:
                    ae:fb:5c:39:72:8f:c0:df:9d:91:93:b9:30:b2:b2:
                    f7:fa:c5:7e:fc:d7:3b:4e:fd:b8:42:a1:19:3f:98:
                    53:c3:05:e3:a8:83:50:1c:51:eb:5a:3e:61:2b:cc:
                    0c:88:8a:5a:91:20:94:f7:5d:85:b1:4d:5f:2d:da:
                    05:45:3f:e9:0b:ea:c1:84:91:7e:57:35:61:60:6e:
                    ae:4f:8c:8a:dd:54:f0:27:77:c9:bb:14:76:46:00:
                    ce:97:2e:23:b1:d6:72:35:92:6a:d3:34:57:14:3c:
                    92:7b:cb:92:94:1d:c0:f1:25:ee:ab:06:01:cf:a1:
                    c6:72:e1:3e:62:bc:e3:72:ed:01:4e:1c:a5:37:9e:
                    25:12:ee:a5:ab:1d:3c:17:fa:6a:a6:4c:6f:a4:32:
                    39:c4:bf:94:29:f3:20:06:06:d5:21:95:f2:80:14:
                    c7:1c:b1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                74:85:80:C0:66:C7:DF:37:DE:CF:BD:29:37:AA:03:1D:BE:ED:CD:17
            X509v3 Subject Key Identifier: 
                6F:FA:B3:B4:E8:6A:BE:D7:6A:6C:E6:23:87:D2:A4:39:87:41:33:2B
            X509v3 Subject Alternative Name: 
                DNS:radius.meraki.com
            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.2
                  CPS: http://www.digicert.com/CPS
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://crl3.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl

                Full Name:
                  URI:http://crl4.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl

            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com
                CA Issuers - URI:http://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt
            X509v3 Basic Constraints: critical
                CA:FALSE
            CT Precertificate SCTs: 
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : 4C:63:DC:98:E5:9C:1D:AB:88:F6:1E:8A:3D:DE:AE:8F:
                                AB:44:A3:37:7B:5F:9B:94:C3:FB:A1:9C:FC:C1:BE:26
                    Timestamp : Jul  1 17:17:29.913 2026 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:46:02:21:00:FB:C1:F0:1A:DE:6E:DE:B1:8A:13:95:
                                B9:10:E1:FC:6B:87:03:AA:0B:D9:13:41:DE:65:50:3C:
                                79:49:8B:AD:E0:02:21:00:EE:72:A3:7B:DE:3C:17:04:
                                20:9E:A7:1E:B0:B9:02:E1:3F:98:F3:1F:1F:82:FA:E2:
                                D6:D3:3E:5E:44:DA:C4:60
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : D6:D5:8D:A9:D0:17:53:F3:6A:4A:A0:C7:57:49:02:AF:
                                EB:C7:DC:2C:D3:8C:D9:F7:64:C8:0C:89:19:1E:9F:02
                    Timestamp : Jul  1 17:17:29.889 2026 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:44:02:20:14:78:96:8D:FD:A1:CC:13:2F:73:2C:26:
                                3B:34:0F:0B:EF:96:CB:B4:F2:7B:86:FC:61:2D:C6:4F:
                                91:C6:0D:22:02:20:14:38:90:F5:13:E0:1F:68:83:C3:
                                FB:0D:3A:0F:DF:6F:6C:C5:37:4C:E2:2F:B0:7B:B4:EA:
                                BA:99:18:6A:8E:94
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : 44:C2:BD:0C:E9:14:0E:64:A5:C9:4A:01:93:0A:5A:A1:
                                BB:35:97:0E:00:EE:11:16:89:68:2A:1C:44:D7:B5:66
                    Timestamp : Jul  1 17:17:29.947 2026 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:44:02:20:54:00:E6:31:DD:19:15:CD:EF:B6:FF:BF:
                                87:98:25:E4:1C:E8:9F:AC:A3:7B:A9:FA:C8:31:63:52:
                                AB:7A:F1:BD:02:20:26:76:81:F1:82:4E:BB:30:4A:F5:
                                35:34:93:E7:82:2C:41:52:29:BA:F9:F4:CB:9C:6B:F4:
                                61:A1:67:3D:C2:19
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        2a:c9:33:14:f0:9c:6c:5b:e1:b8:9c:30:27:c0:80:fd:74:1f:
        a0:c2:26:76:d2:48:0c:28:14:30:cf:06:3f:e6:73:78:7f:29:
        3a:71:86:cf:fc:c7:2f:4c:1c:48:a8:bf:41:70:e4:f9:e4:4d:
        6b:0f:55:ae:95:cc:d1:e5:10:83:ca:8a:1f:b0:e8:de:f6:49:
        e4:31:a6:d8:4c:9e:c1:c0:03:90:41:0b:7a:7a:9f:82:69:ee:
        b6:27:19:ce:1e:31:e7:6e:68:5f:43:39:29:8f:62:04:e9:4d:
        0d:41:2e:39:c8:02:97:38:09:eb:7f:fe:63:7c:aa:ab:1f:d1:
        bd:8e:b3:72:da:65:08:d1:87:e3:cf:d4:41:d1:01:06:3d:62:
        c8:59:dc:85:5e:54:69:fc:c7:5e:21:8a:e3:ff:8d:2d:97:62:
        b3:f8:90:1c:67:57:f3:f5:d3:06:c0:30:c5:c8:65:ae:a5:41:
        ba:69:15:c9:b2:e5:e2:86:80:4b:e8:62:d9:d6:16:c8:4c:78:
        50:58:1c:05:2d:21:e5:29:34:f9:65:cc:5b:be:8d:15:ed:b8:
        ff:e3:85:ef:cf:be:31:85:76:7f:08:a1:ae:62:59:f9:69:67:
        b2:43:c7:91:18:ba:e1:b7:19:0c:67:86:1b:3a:77:f8:14:26:
        d1:95:55:e3

sha256 Fingerprint=10:7A:71:E3:75:A8:5D:6D:56:36:9A:F1:4B:33:23:FC:C6:D9:80:77:5F:8C:56:DB:EE:34:10:99:6F:CD:1B:97
sha1 Fingerprint=D7:C6:6C:3A:35:7F:4A:21:F9:21:1F:B0:ED:85:5F:AC:EB:3A:7F:59

 

  • Was this article helpful?