Uploading Device Certificates

HPE Aruba Networking Central allows you to upload the new and valid device certificate to an existing certificate name listed in the Certificate Management application.

Note:

To upload a device certificate in the Certificate Management application, ensure that you are assigned one of the supported built-in roles: Aruba Central Administrator or Aruba Central View Edit.

To upload certificates, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, click the icon to open the Menu page.

  2. On the Certificate Management card, click Manage.

    The Certificate Management page is displayed.

  3. Click Add on the top-right.

    The Add Certificate page is displayed.

  4. Configure the following parameters:

    • Name—Name of the certificate. You can enter up to a maximum of 20 characters including special characters - and _.

    • Type—Select one of the following certificates from the drop-down list:

      • CA Certificate—Digital certificates issued by the CA.

      • Client Certificate—Client certificates are digital certificates that allow a device or user to prove its identity to a server. Client certificates are used in HPE Aruba Networking Central to authenticate requests made to remote servers.

      • CRL—Certificate Revocation List contains the serial numbers of certificates that have been revoked.

      • OCSP Responder— OCSP responder certificate.

      • OCSP Signer—OCSP response signing certificate.

        Note:

        Online Certificate Status Protocol (OCSP) is used to determine the current status of a digital certificate without requiring a CRL.

      • Server Certificate—Server certificates are required for communication between a device and authentication server.

        Note:

        The Password and Confirm Password parameters are available when you select Client, OCSP Signer, or Server from the Type drop-down list.

    • Format—Select one of the following certificates format from the drop-down list:

      • DER—Distinguished Encoding Rules files are digital certificates in binary format. Both digital certificates and private keys can be encoded in DER format.

      • PEM—Privacy Enhanced Mail is a Base64 encoded DER certificate.

      • PKCS7—Public-Key Cryptography Standards 7 is an archive file format for storing one or more cryptographic objects, such as digital certificates without private keys.

      • PKCS12—Public-Key Cryptography Standards 12 is an archive file format for storing multiple cryptographic objects, such as certificates and private keys, in a single file.

    • Password—Enter a password.

    • Confirm Password—Retype the password for confirmation.

    • Upload Certificate—Click Select File and browse to the location where the certificate is stored and select the certificate file.  

  5. Click Add.

    The certificate is added to the Certificate Management table.