Not sure if that was a question.
Both certificates must be publicly signed-but they don't have to be signed by the same CA.
But if you're using Aruba Central, you don't necessarily have to use ClearPass for guest Wi-Fi. You can use the Central Cloud Guest solution, similar to what's shown in this video.
------------------------------
Regards,
Waldemar
ACCX # 1377, ACEP, ACX - Network Security
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Nov 17, 2025 12:55 AM
From: mohamed-nabil
Subject: External Captive Portal with Aruba Clearpass
Thank you for your reply.
I can use public signed certificate from Aruba Central (CN = Securelogin.hpe.com) for controller and another public signed certificate for Clearpass or 2 Certificates must <wt-ignore uuid="60e58f23-c229-43f6-8ca3-9faff574e6d5" source="wt-feature-result">Sign</wt-ignore> with Same CA.
Original Message:
Sent: Nov 16, 2025 09:23 AM
From: Lord
Subject: External Captive Portal with Aruba Clearpass
Hello,
two certificates are always used in the captive portal setup: one in the controller or gateway, and another in ClearPass. Both certificates must be publicly signed so that guests do not receive a certificate warning in their browser.
In tunneled mode, the gateway is the authenticator and must be configured as a network device in ClearPass.
------------------------------
Regards,
Waldemar
ACCX # 1377, ACEP, ACX - Network Security
If you find my answer useful, consider giving kudos and/or mark as solution
Original Message:
Sent: Nov 15, 2025 09:19 AM
From: mohamed-nabil
Subject: External Captive Portal with Aruba Clearpass
Hello,
I have Scenario The Aruba Gateway and APs of OS 10 will be integrated with the Clearpass Captive Portal, and I will use a Public signed Certificate from Aruba Central (CN = Securelogin.hpe.com) on the Aruba Gateway and APs.
First Question : i will need another Certificate for Clearpass or not
Second Question : APs and Gateways required communications with Clearpass (SSID with Tunneled mode) or Gateways only.
-------------------------------------------