← Integrations

Automated SSL certificate renewal for Aruba Mobility Controller

ArubaOS won't swap in a renewed certificate on its own. CertKit will.

An Aruba Mobility Controller binds two certificates in its web server profile: one for the admin WebUI and one for the captive portal guests sign in on. A renewed certificate does nothing until someone imports it, points the profile at it, and saves, at every node in the Conductor hierarchy that uses it. Every 47 days.

CertKit issues and renews the certificate centrally, then the CertKit Agent connects over SSH, uploads the certificate with SCP, updates the binding, and saves the configuration.

Start free trial Watch demo

Built for Aruba Mobility Controller

Pre-built templates for the admin WebUI and the captive portal ship in your CertKit account. No scripting required.

Pick the WebUI, the captive portal, or both. On a Mobility Conductor, choose the configuration node to update, from /mm/mynode for the Conductor itself to /md or a single group of managed devices.

Either update restarts the controller's web server. Admins sign in again and guests may see a short gap, so schedule renewals in a deployment window.

How to install an SSL certificate on an Aruba controller

The manual process, if you want to do it yourself:

  1. Get the certificate as a PFX. For the captive portal, it must cover the name guest devices resolve to the controller, or guests see name warnings.
  2. Import it. Use Configuration → System → Certificates in the WebUI, or copy it over with SCP and run crypto pki-import from the CLI.
  3. Point the web server at it. In the web-server profile, set switch-cert for the WebUI and captive-portal-cert for the portal.
  4. Save and repeat. Run write memory, then repeat at every node in the hierarchy with its own certificate override.
  5. Clean up. Delete the old certificate once no profile references it.

Every one of these steps is manual, and ArubaOS won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, at every node that uses the certificate. Miss one and guests can't get past the captive portal, or admins get an expired certificate warning on the WebUI.

At 47 days, automation is the only sustainable way to run Aruba Mobility Controller certificates. Here's how CertKit does it.

How it works

 Your network            CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│  ┌─────────────┐  │     │                  │    │             │
│  │Deploy Agent │◄─┼─────┤  Issue & Renew   │◄──►│             │
│  └──┬────┬─────┘  │     │   Certificates   │    │             │
│     │    │SSH     │     │                ┌───┐  └─────────────┘
│     │    │+ SCP   │     └───────────┬────│DNS│
│     ▼    ▼        │                 │    └───┘
│ ┌──────────────┐  │                 │
│ │ Aruba MC     │  │                 │
│ │ [x] Uploaded │  │                 │
│ │ [x] Bound    │  │ ◄───────────────┘
│ │ [x] Saved    │  │       Verify
│ └──────────────┘  │
└───────────────────┘

CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.

The deploy agent runs on a Windows server inside your network. It pulls each renewal from CertKit over outbound HTTPS, then signs in to the controller over SSH. The controller never talks to CertKit, never runs ACME, and never holds DNS credentials.

CertKit has been a fantastic solution for automating our environment’s SSL/TLS certificates. With a single pane of glass for centralized management, visibility, and monitoring and the highly customizable interface for granular control over individual systems, we have found great value in reducing the time and complexity of managing an ad-hoc ACME solution for individual certificate automation.

Seth Allums, Lead Systems and Information Security Engineer, Clackamas Community College

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit.
  2. Prepare the controller. ArubaOS 8.2 or later in the 8.x line. Turn on SCP with service scp and use an admin with the root role.
  3. Install the CertKit Agent. One command on a Windows host that can reach the controller over SSH, plus the Posh-SSH module for all users.
  4. Add the Aruba deployment script. Choose the WebUI or captive portal template, then enter the controller address, credentials, and configuration node.

See the full architecture →

Aruba Mobility Controller deployment requirements and troubleshooting →

Why one renewal can miss half your controllers

In a Conductor hierarchy, a certificate set at /md reaches every managed device, except the groups and devices with their own override. Those keep the old certificate. A manual renewal usually updates the top node and misses the overrides, and the first sign is guests at one site hitting an expired portal.

CertKit runs one deployment per node you configure, and checks each one.

Aruba controllers are one part of your network access stack

Network access touches more than one certificate: Aruba ClearPass for policy and RADIUS, Microsoft Network Policy Server for 802.1X in Windows shops, and firewalls like FortiGate with their own captive portals. CertKit automates all of it from one account.

See all integrations

Start automating Aruba Mobility Controller certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing