Hi Herman,
Today we've done some onsite troubleshooting, testing and packet capturing and I think we found the issue.
After adding the "ca-euw1.cloudguest.central.arubanetworks.com" it stil didn't work.
We made a capture after that on the device itself. This revealed that there also was done a dns resolve for "crl.comodoca.com".
After adding that one to the allowlist url's in the guest splashpage we can now onboard via the guest portal.
(we've added the cloud Auth onboard link in the Terms & Conditions to make onboarding easy)
My guess is that there is a CRL check done in the Aruba onboard App for the server certificate before requesting the usercertificate that is used for authenticating on the passpoint SSID
Thank you for pushing us into the right direction.
-------------------------------------------
Original Message:
Sent: Mar 03, 2026 10:52 AM
From: Herman Robers
Subject: Which URL are used for the Aruba Onboard Network Profile
Have you opened up the URLs mentioned in the documentation already? Then most specific the Guest related URLs?
UPDATE: I ran a network capture, and it seems there is access needed to the CA as well:
You are probably on another Central cluster, but putting ca- in front of the cloudguest URL may do the job.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------