Tag: Undo |
|||
| (3 intermediate revisions by the same user not shown) | |||
| Line 123: | Line 123: | ||
<pre> | <pre> | ||
/certificate print | [admin@Courvoisier] > /certificate print | ||
Flags: K - PRIVATE-KEY; A - AUTHORITY; I - ISSUED; T - TRUSTED | |||
Columns: NAME, COMMON-NAME, SKID | |||
# NAME COMMON-NAME SKID | |||
0 KA T CAPsMAN-CA-488F5A87BE5A CAPsMAN-CA-488F5A87BE5A b96a4f946961524e913ad4703868303a0dd23c9b | |||
1 K I CAPsMAN-488F5A87BE5A CAPsMAN-488F5A87BE5A cf5b50d734e8ef10c1257577bb6783890c06b55c | |||
2 I CAP-08553163AC8E CAP-08553163AC8E 71c4e6af7e09cf386dad50ec271c41f9e6a62e7a | |||
3 I CAP-08553163A40F CAP-08553163A40F d7123f8e1e7d616edbc4b7bda20a610ed5becd0b | |||
4 KA T WiFi-CAPsMAN-CA-488F5A87BE5A WiFi-CAPsMAN-CA-488F5A87BE5A c65a58c80dd0ee06a84721ca46439882b5157fea | |||
5 K I WiFi-CAPsMAN-488F5A87BE5A WiFi-CAPsMAN-488F5A87BE5A caaa1c14fd8e0ee03458616e450cc81d85706cca | |||
</pre> | </pre> | ||
| Line 131: | Line 140: | ||
* CA certificate | * CA certificate | ||
TWe want: | |||
<pre> | <pre> | ||
CAPsMAN- | WiFi-CAPsMAN-CA-488F5A87BE5A | ||
WiFi-CAPsMAN-488F5A87BE5A | |||
</pre> | </pre> | ||
| Line 145: | Line 154: | ||
<pre> | <pre> | ||
/certificate export-certificate CAPsMAN- | /certificate export-certificate WiFi-CAPsMAN-488F5A87BE5A export-passphrase=StrongPass | ||
/certificate export-certificate | /certificate export-certificate WiFi-CAPsMAN-CA-488F5A87BE5A export-passphrase=StrongPass | ||
</pre> | </pre> | ||
| Line 152: | Line 161: | ||
<pre> | <pre> | ||
/file print | [admin@Courvoisier] > /file print | ||
# NAME TYPE SIZE LAST-MODIFIED | |||
0 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key .key file 497 2026-03-14 13:23:47 | |||
1 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt .crt file 672 2026-03-14 13:23:47 | |||
2 cert_export_WiFi-CAPsMAN-488F5A87BE5A.key .key file 497 2026-03-14 13:23:07 | |||
3 cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt .crt file 688 2026-03-14 13:23:07 | |||
4 flash disk 2026-03-14 00:00:34 | |||
5 flash/Courvoisier-export.rsc script 29.7KiB 2026-03-14 00:00:34 | |||
6 flash/skins directory 2106-02-07 02:28:42 | |||
7 flash/auto-before-reset.backup backup 18.7KiB 2106-02-07 02:28:48 | |||
8 flash/pub directory 2020-09-11 01:10:52 | |||
9 flash/Courvoisier-daily.backup backup 114.3KiB 2026-03-14 00:00:01 | |||
</pre> | </pre> | ||
Exported files: | |||
* CAPsMAN- | * cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key | ||
* CAPsMAN- | * cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt | ||
* | * cert_export_WiFi-CAPsMAN-488F5A87BE5A.key | ||
* cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt | |||
---- | ---- | ||
| Line 176: | Line 197: | ||
scp *.crt admin@absolut:/ | scp *.crt admin@absolut:/ | ||
scp *.key admin@absolut:/ | scp *.key admin@absolut:/ | ||
</pre> | </pre>''This had to be done using a Linux system as a waystation because RouterOS had no scp client.'' | ||
---- | ---- | ||
| Line 185: | Line 205: | ||
<pre> | <pre> | ||
/certificate import file-name=CAPsMAN- | /certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt passphrase=StrongPass | ||
/certificate import file-name=CAPsMAN- | /certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key passphrase=StrongPass | ||
/certificate import file-name= | |||
/certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt passphrase=StrongPass | |||
/certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.key passphrase=StrongPass | |||
</pre> | </pre> | ||
| Line 193: | Line 215: | ||
<pre> | <pre> | ||
/certificate print | [admin@Absolut] > /certificate print | ||
</pre> | Flags: K - PRIVATE-KEY; A - AUTHORITY; T - TRUSTED | ||
Columns: NAME, COMMON-NAME, SKID | |||
# NAME COMMON-NAME SKID | |||
0 KAT cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0 WiFi-CAPsMAN-CA-488F5A87BE5A c65a58c80dd0ee06a84721ca46439882b5157fea | |||
1 K T cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0 WiFi-CAPsMAN-488F5A87BE5A caaa1c14fd8e0ee03458616e450cc81d85706cca | |||
</pre>Note that the SKIDs on '''absolut''' match those on '''courvoisier'''. | |||
''There were some crap autogenerated certificates from prior to migration, but i elected to remove those now.'' | |||
---- | ---- | ||
| Line 203: | Line 231: | ||
<pre> | <pre> | ||
/caps-man manager set | /caps-man manager set \ | ||
certificate=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0 \ | |||
ca-certificate=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0 \ | |||
enabled=yes | |||
</pre> | </pre> | ||
| Line 211: | Line 240: | ||
<pre> | <pre> | ||
/caps-man manager print | [admin@Absolut] > /caps-man manager print | ||
</pre> | enabled: yes | ||
certificate: cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0 | |||
ca-certificate: cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0 | |||
package-path: | |||
upgrade-policy: none | |||
require-peer-certificate: no | |||
generated-certificate: *2 | |||
generated-ca-certificate: *1 | |||
</pre>The *1 and *2 references are the autogenerated certs that i removed. they are not used and this is supposed to be harmless. | |||
---- | ---- | ||
| Line 233: | Line 269: | ||
<pre> | <pre> | ||
/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \ | /interface eoip add name=EOIP.KitsNetG.to.Courvoisier \ | ||
local-address= | local-address=192.168.15.10 \ | ||
remote-address=192.168.15.6 \ | remote-address=192.168.15.6 \ | ||
tunnel-id=120 | tunnel-id=120 | ||
| Line 259: | Line 295: | ||
/interface eoip add name=EOIP.KitsNetG.to.Absolut \ | /interface eoip add name=EOIP.KitsNetG.to.Absolut \ | ||
local-address=192.168.15.6 \ | local-address=192.168.15.6 \ | ||
remote-address= | remote-address=192.168.15.10 \ | ||
tunnel-id=120 | tunnel-id=120 | ||
</pre> | </pre> | ||
| Line 278: | Line 314: | ||
<pre> | <pre> | ||
/interface wireless cap set caps-man-addresses= | /interface wireless cap set caps-man-addresses=192.168.15.10 | ||
</pre> | </pre> | ||
| Line 307: | Line 343: | ||
<pre> | <pre> | ||
/interface wireless cap set caps-man-addresses= | /interface wireless cap set caps-man-addresses=192.168.15.10 | ||
</pre> | </pre> | ||
| Line 330: | Line 366: | ||
<pre> | <pre> | ||
/interface wireless cap set lock-to-caps-man=yes | /interface wireless cap set lock-to-caps-man=yes | ||
</pre> | </pre>'''''We cannot lock to caps yet becuase we don't have certificate locking working. I tried this now and Able would not associate with CAPsMAN at all. this has to wait for a post-migration activity.''''' | ||
---- | ---- | ||
Latest revision as of 15:05, 14 March 2026
1 CAPsMAN Migration: Courvoisier → Absolut[edit | edit source]
This document describes the complete migration of CAPsMAN control from courvoisier to the CHR instance absolut while preserving the existing DHCP architecture and ensuring that wireless client traffic does not traverse the CHR in the final design.
The migration is performed in two stages:
- Interim migration state – CAPsMAN moves to Absolut while Guest traffic may temporarily traverse the CHR.
- Final controller-only state – wireless client traffic no longer passes through Absolut.
1.1 Supporting Configuration Patch Files[edit | edit source]
- File:Courvoisier-final-post-migration-patch.rsc.txt
- File:Absolut-final-controller-only-patch.rsc.txt
- File:Courvoisier-interim-guest-transport-patch.rsc.txt
- File:Absolut-interim-migration-patch.rsc.txt
1.2 Architecture Context[edit | edit source]
| Component | Role |
|---|---|
| absolut | CAPsMAN controller (control plane only) |
| courvoisier | edge router and Guest DHCP server |
| radix.kitsnet.us (192.168.15.1) | DHCP server for main LAN and IoT network |
Wireless data traffic should remain on the physical LAN through the CAP devices and should not traverse the CHR once migration is complete.
1.3 SSID Design[edit | edit source]
| SSID | Purpose | DHCP Source |
|---|---|---|
| KitsNet | trusted WLAN | radix.kitsnet.us |
| KitsNetIN | IoT network | radix.kitsnet.us |
| KitsNetGN | guest WLAN | courvoisier |
1.4 Preconditions[edit | edit source]
Before beginning the migration verify:
1.4.1 CAP registration[edit | edit source]
On courvoisier:
/caps-man remote-cap print detail
Expected:
- able – Run
- baker – Run
1.4.2 CAP configuration[edit | edit source]
On able and baker:
/interface wireless cap print
Verify:
enabled: yes lock-to-caps-man: no caps-man-addresses: 192.168.15.6
1.4.3 Guest DHCP[edit | edit source]
On courvoisier:
/ip dhcp-server print detail
Confirm the DHCP server is bound to bridge:
BWF.KitsNetG
1.5 CAPsMAN Certificate Migration[edit | edit source]
The CAPsMAN controller identity must be preserved during migration. The active CAPsMAN certificate and CA must be copied from courvoisier to absolut.
This avoids CAP authentication failures or WPA handshake problems.
1.5.1 Step 1 – Identify certificates[edit | edit source]
On courvoisier:
[admin@Courvoisier] > /certificate print Flags: K - PRIVATE-KEY; A - AUTHORITY; I - ISSUED; T - TRUSTED Columns: NAME, COMMON-NAME, SKID # NAME COMMON-NAME SKID 0 KA T CAPsMAN-CA-488F5A87BE5A CAPsMAN-CA-488F5A87BE5A b96a4f946961524e913ad4703868303a0dd23c9b 1 K I CAPsMAN-488F5A87BE5A CAPsMAN-488F5A87BE5A cf5b50d734e8ef10c1257577bb6783890c06b55c 2 I CAP-08553163AC8E CAP-08553163AC8E 71c4e6af7e09cf386dad50ec271c41f9e6a62e7a 3 I CAP-08553163A40F CAP-08553163A40F d7123f8e1e7d616edbc4b7bda20a610ed5becd0b 4 KA T WiFi-CAPsMAN-CA-488F5A87BE5A WiFi-CAPsMAN-CA-488F5A87BE5A c65a58c80dd0ee06a84721ca46439882b5157fea 5 K I WiFi-CAPsMAN-488F5A87BE5A WiFi-CAPsMAN-488F5A87BE5A caaa1c14fd8e0ee03458616e450cc81d85706cca
Identify:
- CAPsMAN certificate
- CA certificate
TWe want:
WiFi-CAPsMAN-CA-488F5A87BE5A WiFi-CAPsMAN-488F5A87BE5A
1.5.2 Step 2 – Export certificates[edit | edit source]
On courvoisier:
/certificate export-certificate WiFi-CAPsMAN-488F5A87BE5A export-passphrase=StrongPass /certificate export-certificate WiFi-CAPsMAN-CA-488F5A87BE5A export-passphrase=StrongPass
Generated files will appear in:
[admin@Courvoisier] > /file print # NAME TYPE SIZE LAST-MODIFIED 0 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key .key file 497 2026-03-14 13:23:47 1 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt .crt file 672 2026-03-14 13:23:47 2 cert_export_WiFi-CAPsMAN-488F5A87BE5A.key .key file 497 2026-03-14 13:23:07 3 cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt .crt file 688 2026-03-14 13:23:07 4 flash disk 2026-03-14 00:00:34 5 flash/Courvoisier-export.rsc script 29.7KiB 2026-03-14 00:00:34 6 flash/skins directory 2106-02-07 02:28:42 7 flash/auto-before-reset.backup backup 18.7KiB 2106-02-07 02:28:48 8 flash/pub directory 2020-09-11 01:10:52 9 flash/Courvoisier-daily.backup backup 114.3KiB 2026-03-14 00:00:01
Exported files:
- cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key
- cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt
- cert_export_WiFi-CAPsMAN-488F5A87BE5A.key
- cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt
1.5.3 Step 3 – Transfer certificates to Absolut[edit | edit source]
Copy the files to absolut using:
- WinBox file transfer
- SCP
- FTP
Example using SCP:
scp *.crt admin@absolut:/ scp *.key admin@absolut:/
This had to be done using a Linux system as a waystation because RouterOS had no scp client.
1.5.4 Step 4 – Import certificates on Absolut[edit | edit source]
On absolut:
/certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt passphrase=StrongPass /certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key passphrase=StrongPass /certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt passphrase=StrongPass /certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.key passphrase=StrongPass
Verify:
[admin@Absolut] > /certificate print Flags: K - PRIVATE-KEY; A - AUTHORITY; T - TRUSTED Columns: NAME, COMMON-NAME, SKID # NAME COMMON-NAME SKID 0 KAT cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0 WiFi-CAPsMAN-CA-488F5A87BE5A c65a58c80dd0ee06a84721ca46439882b5157fea 1 K T cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0 WiFi-CAPsMAN-488F5A87BE5A caaa1c14fd8e0ee03458616e450cc81d85706cca
Note that the SKIDs on absolut match those on courvoisier.
There were some crap autogenerated certificates from prior to migration, but i elected to remove those now.
1.5.5 Step 5 – Assign certificates to CAPsMAN[edit | edit source]
On absolut:
/caps-man manager set \ certificate=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0 \ ca-certificate=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0 \ enabled=yes
Verify:
[admin@Absolut] > /caps-man manager print
enabled: yes
certificate: cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0
ca-certificate: cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0
package-path:
upgrade-policy: none
require-peer-certificate: no
generated-certificate: *2
generated-ca-certificate: *1
The *1 and *2 references are the autogenerated certs that i removed. they are not used and this is supposed to be harmless.
1.6 Stage A – Interim Migration State[edit | edit source]
During migration Guest traffic may temporarily traverse Absolut in order to maintain connectivity with the Guest DHCP server on courvoisier.
1.6.1 Prepare Absolut[edit | edit source]
Create temporary Guest bridge:
/interface bridge add name=BWF.KitsNetG
Create EoIP tunnel to courvoisier:
/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \ local-address=192.168.15.10 \ remote-address=192.168.15.6 \ tunnel-id=120
Attach the tunnel to the bridge:
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Courvoisier
Update the Guest datapath:
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=no bridge=BWF.KitsNetG
1.6.2 Prepare Courvoisier[edit | edit source]
Create the matching EoIP interface:
/interface eoip add name=EOIP.KitsNetG.to.Absolut \ local-address=192.168.15.6 \ remote-address=192.168.15.10 \ tunnel-id=120
Attach to Guest bridge:
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Absolut
1.7 Migration Procedure[edit | edit source]
1.7.1 Step 1 – Move Able[edit | edit source]
On able:
/interface wireless cap set caps-man-addresses=192.168.15.10
Verify on Absolut:
/caps-man remote-cap print /caps-man interface print
Test:
- KitsNet connectivity
- Guest DHCP
- IoT connectivity
Rollback if needed:
/interface wireless cap set caps-man-addresses=192.168.15.6
1.7.2 Step 2 – Move Baker[edit | edit source]
On baker:
/interface wireless cap set caps-man-addresses=192.168.15.10
Verify both CAPs:
/caps-man remote-cap print
1.7.3 Step 3 – Disable CAPsMAN on Courvoisier[edit | edit source]
Once both CAPs are stable:
/caps-man manager set enabled=no
Lock CAPs:
/interface wireless cap set lock-to-caps-man=yes
We cannot lock to caps yet becuase we don't have certificate locking working. I tried this now and Able would not associate with CAPsMAN at all. this has to wait for a post-migration activity.
1.8 Validation[edit | edit source]
On absolut:
/caps-man registration-table print
On courvoisier:
/ip dhcp-server lease print
Verify:
- clients on KitsNet obtain DHCP from Radix
- guest clients obtain DHCP from Courvoisier
- CAPs remain connected to Absolut
1.9 Rollback[edit | edit source]
If migration fails revert CAPs to Courvoisier.
On CAP:
/interface wireless cap set caps-man-addresses=192.168.15.6
Re-enable CAPsMAN:
/caps-man manager set enabled=yes
1.10 Stage B – Final Controller-Only State[edit | edit source]
After a permanent Guest L2 path exists outside the CHR:
On absolut:
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=yes
Remove temporary EoIP:
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Courvoisier"] /interface eoip remove EOIP.KitsNetG.to.Courvoisier /interface bridge remove BWF.KitsNetG
On courvoisier:
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Absolut"] /interface eoip remove EOIP.KitsNetG.to.Absolut
1.11 Final State[edit | edit source]
- Absolut runs CAPsMAN only
- Courvoisier continues Guest DHCP
- Radix provides LAN DHCP
- CAPs locally forward client traffic
- No wireless data traffic traverses the CHR