Changes to your RADIUS server, don't need a restart of the controller/APs.
If you change the RADIUS server certificate, especially to a new Root CA you should reprovision your clients. It's strongly recommended to do that through a device management tool, like group policies, or MDM/EMM tooling. Clients should properly verify the RADIUS server certificate to keep the network, and if you use MSCHAPv2 (DEPRECATED because of weak security) the user credentials.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------