The CN on HTTPS certificates is no longer relevant, just SANs count. And for guest flows, the controller, ClearPass and possible other servers that need to be reached during the login, will require a different FQDN, and each server should have a certificate that is valid for it's FQDN. That can be through separate certificates (which has a single SAN), or one/more certificates that have multiple SANs, wildcard (SAN contains a *) or any combination as long as you meet the requirement that the certificate for the server has a SAN that matches its FQDN to prevent certificate warnings.
You may check this video, then the controller initiated guest workflow for possible better understanding how certificates work in a guest scenario. Because in my experience some people may find certificates hard to understand, it may be good to ask your Aruba partner for assistance.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------