Check this video. With the change that in newer versions of Instant like 8.6, you can configure all from the WebUI.
If you return the role names, or DUR, from the ClearPass, you can leave the access to unrestricted, or apply a network policy that blocks most of the traffic in can you don't return a role. It is expected that if you don't do any role-assignment for 'role-based' and don't have a network based policy, that the UI jumps back to unrestricted. The Aruba-User-Role attributes, and the CPPM-User-Role just overrides whatever is set for the access policy locally on the AP. What you describe sounds like expected and not an issue.
For 802.1X, you don't need a certificate on the Instant AP.
For DUR, you need a signed certificate on the ClearPass HTTPS, and you need to configure the ClearPass RADIUS in the IAP based on the hostname, which should match one of the SANs in your HTTPS certificate on ClearPass.
For Guest operations, like captive portal, you will need a public trusted certificate on the IAP to prevent certificate warnings for your guests. If your AP is in Central, you can assign the 'aruba_default' certificate, which will push a trusted certificate from Central, or you can upload your own to Central and deploy that.
If you don't use the captive portal, no certificate is needed on the IAP.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------