Built for Aruba Mobility Controller
Pre-built templates for the admin WebUI and the captive portal ship in your CertKit account. No scripting required.
An Aruba Mobility Controller binds two certificates in its web server profile: one for the admin WebUI and one for the captive portal guests sign in on. A renewed certificate does nothing until someone imports it, points the profile at it, and saves, at every node in the Conductor hierarchy that uses it. Every 47 days.
CertKit issues and renews the certificate centrally, then the CertKit Agent connects over SSH, uploads the certificate with SCP, updates the binding, and saves the configuration.
Pre-built templates for the admin WebUI and the captive portal ship in your CertKit account. No scripting required.
Pick the WebUI, the captive portal, or both. On a Mobility Conductor, choose the
configuration node to update, from /mm/mynode for the Conductor itself to
/md or a single group of managed devices.
Either update restarts the controller's web server. Admins sign in again and guests may see a short gap, so schedule renewals in a deployment window.
The manual process, if you want to do it yourself:
crypto pki-import from the CLI.
web-server profile, set switch-cert for the WebUI and captive-portal-cert for the portal.
write memory, then repeat at every node in the hierarchy with its own certificate override.
Every one of these steps is manual, and ArubaOS won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, at every node that uses the certificate. Miss one and guests can't get past the captive portal, or admins get an expired certificate warning on the WebUI.
At 47 days, automation is the only sustainable way to run Aruba Mobility Controller certificates. Here's how CertKit does it.
Your network CertKit ACME CA ┌───────────────────┐ ┌──────────────────┐ ┌─────────────┐ │ ┌─────────────┐ │ │ │ │ │ │ │Deploy Agent │◄─┼─────┤ Issue & Renew │◄──►│ │ │ └──┬────┬─────┘ │ │ Certificates │ │ │ │ │ │SSH │ │ ┌───┐ └─────────────┘ │ │ │+ SCP │ └───────────┬────│DNS│ │ ▼ ▼ │ │ └───┘ │ ┌──────────────┐ │ │ │ │ Aruba MC │ │ │ │ │ [x] Uploaded │ │ │ │ │ [x] Bound │ │ ◄───────────────┘ │ │ [x] Saved │ │ Verify │ └──────────────┘ │ └───────────────────┘
CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.
The deploy agent runs on a Windows server inside your network. It pulls each renewal from CertKit over outbound HTTPS, then signs in to the controller over SSH. The controller never talks to CertKit, never runs ACME, and never holds DNS credentials.
CertKit has been a fantastic solution for automating our environment’s SSL/TLS certificates. With a single pane of glass for centralized management, visibility, and monitoring and the highly customizable interface for granular control over individual systems, we have found great value in reducing the time and complexity of managing an ad-hoc ACME solution for individual certificate automation.
Seth Allums, Lead Systems and Information Security Engineer, Clackamas Community College
switch-cert or captive-portal-cert. A second template reuses the installed certificate.
/md, or one group. Overrides on child nodes stay put and get their own deployment.
write memory, then removes older copies it installed at that node. It never deletes certificates it didn't install or ones still in use.
service scp and use an admin with the root role.
Aruba Mobility Controller deployment requirements and troubleshooting →
In a Conductor hierarchy, a certificate set at /md reaches every managed
device, except the groups and devices with their own override. Those keep the old certificate.
A manual renewal usually updates the top node and misses the overrides, and the first sign is
guests at one site hitting an expired portal.
CertKit runs one deployment per node you configure, and checks each one.
Network access touches more than one certificate: Aruba ClearPass for policy and RADIUS, Microsoft Network Policy Server for 802.1X in Windows shops, and firewalls like FortiGate with their own captive portals. CertKit automates all of it from one account.
Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.