Device Certificate Management

HPE Aruba Networking Central allows you to manage digital certificates that are pushed to the networking devices. These certificates are used to establish trust and enable secure authentication between network entities—such as networking devices, upstream servers, and downstream clients—during scenarios like RADIUS-based authentication. Certificates are deployed from Classic Central to networking devices, which store them locally. Devices use these certificates to authenticate themselves when operating as clients, or to authenticate peers and endpoints when operating as servers or authenticators.

In addition to uploading custom certificates issued by a trusted Certificate Authority (CA), you can also import one or multiple certificates directly from Classic Central. This makes it easier to deploy pre-issued certificates across devices. Replacing default device certificates with site or domain-specific certificates enhances security for certificate-based authentication.

Note:
  • HPE Aruba Networking Central recommends that you replace the default certificate with a custom certificate issued for your site or domain by a trusted CA. It is applicable only for non-appliance (TPM-disabled) environment.

  • HPE Aruba Networking Central supports role-based access control (RBAC) such as, Create, Read, and Delete to manage and perform various actions within the Certificate Management application.

  • Ensure that the same certificate is uploaded to both Classic Central and HPE Aruba Networking Central with identical certificate names.