Cisco Keeper to PureCA Migration Strategy
Overview
This guide outlines the migration of Cisco Wireless Access Point from Cisco Keeper PKI backend to the modernized PureCA service. It provides a roadmap for transitioning features like RADsec, Zigbee, and OpenRoaming to ensure continued certificate-based support after Cisco Keeper legacy deprecation.
Key benefits of PureCA design
-
Enhanced Security: Implements a structured Certificate Hierarchy where device certificates are signed by specific Feature CAs.
-
Modernized Infrastructure: Transitions from HashiCorp Vault-managed instances (Keeper) to Cisco’s newer PKI service.
-
Future-Proofing: Establishes a permanent solution for certificate issuance and management as legacy systems are deprecated.
Transition Timeline from Keeper to PureCA
Please be aware of the following schedule regarding certificate generation and the deprecation of Keeper:
-
July 15th 2026 (MR 33.1.2 Release): PureCA is now available. While Keeper is still supported, completing the PureCA generation flow will override your existing Keeper certificate. Access Points running versions older than MR 33 will continue to use Keeper.
-
August to October 2026: Backwards compatibility with access points running firmware older than 33.1.2 release will be introduced during a gradual rollout. This includes Wi-Fi 5 wave2 APs that cannot be upgraded beyond MR 30.7. If you experience issues during this phase, you will have the ability to revert to your existing Keeper certificate.
-
November 2026 (Keeper Deprecation): Keeper will be officially deprecated. If you have already completed the PureCA flow, this will not affect you. However, if you are still exclusively using a Keeper certificate, it will not be able to be authorized and cease to function. Please plan your transition accordingly.
Impacted Features
RADSec, Zigbee, and OpenRoaming features utilizing certificate-based authentication will be impacted by this change.
Best Practices
Recommended Upgrade Path
-
Phased Upgrade: Upgrade networks requiring PureCA certificates to R33.1.2 as early as possible within the July to November 2026 window.
-
Pre-emptive Trust: Export the new Issuer/Trust Chain and approve Root Anchor pinning in advance of the full cutover.
-
Backward Compatibility: Utilize the dual-trust transition period (July–Nov 2026) to manage mixed firmware version organizations.
Security Considerations and Compliance
-
Policy Updates: Review and update strict certificate policies associated with various fields in the new PureCA certificates if required.
-
Root Anchor Management: Ensure the Meraki Root and Org Root anchors are correctly trusted during the transition.
-
Revocation Awareness: Understand the specific revocation behavior and renewal timing of the new PureCA hierarchy.
Technical Architecture
The migration shifts from a flat HashiCorp Vault signing structure to a multi-tiered hierarchy.
-
Legacy Keeper Structure: Dashboard uses a Vault instance to generate self-signed CAs per organization and sign CSRs directly for MR nodes.
-
PureCA Structure: A centralized Meraki Root signs an Org Root, which in turn signs an Org CA and specific FeatureCAs (e.g., RadSec or Zigbee). Device certificates are signed by these FeatureCAs.
Between June and November 2026, the Organization>Certificates page will display both legacy and PureCA sections for the impacted features to monitor status across mixed-version networks.
FAQs
General Overview
What is the PureCA migration?
The PureCA migration is the transition of Meraki MR certificate management from the legacy Cisco Keeper PKI backend (managed via HashiCorp Vault) to Cisco's modernized PureCA service. This ensures continued, future-proof certificate-based support for features after the legacy system is deprecated.
What are the key benefits of moving to PureCA?
-
Enhanced Security: Introduces a structured, multi-tiered certificate hierarchy where device certificates are signed by specific Feature Certificate Authorities (FeatureCAs).
-
Modernized Infrastructure: Shifts away from legacy Vault instances to Cisco’s current, enterprise-grade PKI service.
-
Future-Proofing: Provides a permanent, scalable solution for certificate issuance and management.
Impact & Requirements
Which features and devices are impacted?
This migration impacts all access points utilizing certificate-based authentication for RadSec, OpenRoaming and Zigbee functionalities.
Architecture & Technical Details
How does the PureCA architecture differ from the legacy Keeper system?
-
Legacy Keeper Structure: Utilized a "flat" structure where Dashboard used a HashiCorp Vault instance to generate self-signed CAs per organization, signing Certificate Signing Requests (CSRs) directly for MR nodes.
-
New PureCA Structure: Utilizes a multi-tiered hierarchy. A centralized Meraki Root signs an Org Root, which then signs an Org CA and distinct FeatureCAs (e.g., a specific CA for RADSec and another for Zigbee). Device certificates are finally signed by these individual FeatureCAs.
How will PureCA handle scale and API performance?
PureCA inherently scales better by isolating certificate signing across different FeatureCAs. Because processing times may vary, new PureCA API calls should be treated as asynchronous. It is also recommended to utilize scheduled update windows to minimize overlapping certificate renewals.
For more information on API, refer to the developer documentation.
Timeline, Best Practices and Monitoring
What is the timeline for the migration?
The dual-trust transition period will take place between June and November 2026. Full deprecation of the legacy Cisco Keeper system will occur in November 2026.
What are the recommended best practices for a seamless cutover?
-
Phased Upgrades: Upgrade networks requiring PureCA certificates to R33.1.1 as early as possible within the transition window.
-
Pre-emptive Trust: Export the new Issuer/Trust Chain and approve Root Anchor pinning (ensuring both Meraki Root and Org Root anchors are trusted) before the full cutover.
-
Policy Updates: Review and update any strict certificate policies associated with fields in the new PureCA certificates.
-
Revocation Awareness: Familiarize your team with the specific revocation behavior and renewal timing introduced by the new hierarchy.
How can I monitor the status of my networks during the transition?
Cisco will implement a dual-trust strategy to minimize downtime. Between June and November 2026, the Orginzation>Certificates page will display both legacy and PureCA sections, allowing administrators to monitor status across mixed-version environments.


