Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Uploading Certificates
To upload certificates, complete the following steps:
- In the WebUI, set the filter to .
- Under , click .
The Network Structure tab is displayed.
- Click the tile.
The Certificates page is displayed.
- Expand the accordion to view the table.
- Click the + icon to add the certificate to the .
- In the dialog box, specify the following information:
- —Name of the certificate.
- —Select of certificate type. You can select any one of the following certificates:
- —Server certificates are used between browsers and HPE Aruba Networking Central On-Premises to access the HPE Aruba Networking Central On-Premises UI User Interface. . A server certificate is also required for communication between a device and HPE Aruba Networking Central On-Premises, when a device is selected in supported services.
- —Digital certificates issued by the CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. . If a user intends to upload multiple CA certificates, HPE Aruba Networking Central On-Premises allows you to combine and upload the certificates as a single CA certificate.
The Operation Type option is applicable only when you select from the drop-down list.
- Client Certificate—Client certificates are digital certificates for users to prove their identity to a server. Client certificates are used in HPE Aruba Networking Central On-Premises to authenticate requests made to remote servers.
The , , and options are applicable when you select or from the drop-down list.
- —Select a certificate format. You can select any one of the following certificates:
- PEM—Privacy Enhanced Mail is a Base64 encoded DER certificate.
- DER—Distinguished Encoding Rules files are digital certificates in binary format. Both digital certificates and private keys can be encoded in DER format.
- PKCS12—Public-Key Cryptography Standards 12 is an archive file format for storing many cryptography objects as a single file.
The DER certificate format is not applicable when you select Server Certificate from the Type drop-down list.
The PKCS12 certificate format option is not applicable when you select CA Certificate from the Type drop-down list.
- Services Supported—Select the services to be supported by the certificate. A single server certificate can be used for more that one supported services.
- Web UI And API Gateway—The server certificate is applied to WebUI and API Gateway service. The Web UI And API Gateway support RSA Rivest, Shamir, Adleman. RSA is a cryptosystem for public-key encryption, and is widely used for securing sensitive data, particularly when being sent over an insecure network such as the Internet. and Elliptical Curve Cryptography (ECC) certificate. Only prime256v1, secp256r1, secp384r1 and secp521r1 types of ECC curves are supported.
- Device—The server certificate is applied to device service.
- Secure AMON—The server certificate is applied to Secure Advanced Monitoring (SAMON) service. To use Server certificates on HPE Aruba Networking Central On-Premises, the SAMON service uses DTLS Datagram Transport Layer Security is a communications protocol providing security to datagram-based applications by allowing them to communicate in a way designed to prevent tampering, message forgery or eavesdropping. protocol.
- RadSec—The server certificate is applied to verify RadSec protocol. RadSec service secures the communication between the HPE Aruba Networking Central On-Premises and RADIUS Remote Authentication Dial-In User Service is a networking protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service server.
Web UI And API Application Programming Interface. Refers to a set of functions, procedures, protocols, and tools that enable users to build application software. Gateway, Device and Secure AMON Advanced Monitoring. AMON is used in Aruba WLAN deployments for improved network management, monitoring, and diagnostic capabilities. services are available when you select from the drop-down list.
Only RadSec RadSec is an authentication and authorization protocol for transporting RADIUS datagrams over TCP and TLS. service is available when you select from the drop-down list.
- Operation Type—Select the action required while adding CA certificates. The Operation Type option is applicable when you select CA Certificate from the Type drop-down list. You can select any one of the following options:
- Append—Adds the new CA certificates to the uploaded CA certificates along with its default list of certificates. You can add a maximum of 10 CA certificates to the default list.
- Replace—Retains the default list and replaces the user-uploaded certificates only.
- —Enter a passphrase that was used while generating the Private Key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender. .
- —Retype the passphrase for confirmation.
- —Click and browse to the location where the certificates are stored and select the certificate files.
- Click .
The certificate is added to the table.
HPE Aruba Networking Central On-Premises does not allow you to edit or delete the appliance certificates.