Wireless Access

Contributor I

[Tutorial] How to replace SSL certificate.



Just wanted to write this tutorial since it's a very current issue. (BTW I get nothing from Godaddy :) )


This tutorial is called "How to replace Captive Portal SSL certificate and get NO invalid certificate complains from browser"

Generate certificate request using linux and command line (DON'T generate CSR request on your controller, It's just simply not needed)


openssl req -nodes -newkey rsa:2048 -keyout securelogin.mycompany.com.key -out securelogin.mycompany.com.csr


You will be asked few things like country, company name and such. After you're done you have created CSR file and KEY file.

Go to godaddy.com and login (or create a login if not existing) and choose "Products > SSL&Security > Standard SSL > Single domain, I recommend to take at least 3 years for about 200€ Inc. Taxes. And you can use this same certificate on multiple controllers with no extra costs!

Now at certificate manage site you will be asked CSR so copy paste CONTENT of your csr file you just created.
It looks like this (Include everything)





Choose SHA2 and 2048Bits, leave everything else like it is.


Next thing is to validate your certificate request and for that you have few options.

1. Request approval to your domains admins email (You'll get an approval email with approve link)

  you can check what is your domain admins email address on WHOIS database from here http://whois.domaintools.com



2. Add an text string given you by godaddy to your website, and some Godaddy robot will check that the text string can really be found from you website.


Method 1 is faster, I got my certificate in just 3-4 hours from my request.

When you certificate is approved and generated you'll get an download link or you can login to your Godaddy acoount and download it, When you are downloding you'll be asked to choose server type, just choose "other" and download.


In the download package you get 2 files:


One is some numbers and letters.crt (example 65jheh96798.crt) and other is gd_bundle-2g.crt

You need to compine these two certificates, so open up 65jheh96798.crt and paste the WHOLE CONTENT of gd_bundle-g2.crt right after -----END CERTIFICATE-----


Now go back to linux, upload these two file on same location you have CSR and KEY file and run command


openssl pkcs12 -export -out securelogin.mycompany.com.pfx -inkey securelogin.mycompany.com.key -in 65jheh96798.crt -certfile 65jheh96798.crt

Password will be asked during generate progess, just type whatever password you want.


You have now successfully generated your pfx certificate called securelogin.mycompany.com.pfx, upload that you your computer.


Next thing is to upload certificate to your controller, so login to your controller / controllers and upload certificate Configuration > Certificates >

Give a name to your certificate and choose your .pfx file

Type in your certificates password

Format pfx

Certificate type Server cert


Now start using your new certificate and go to General and choose Captiveportal certificate as your new certificate and you're done.

If you are using external captive portal remember to change HTML code part from:

<form method="post" autocomplete="off" action="https://securelogin.arubanetworks.com/auth/index.html/u" onsubmit="return checkFormValues(this);">




<form method="post" autocomplete="off" action="https://securelogin.mycompany.com/auth/index.html/u" onsubmit="return checkFormValues(this);">



You're done!


Best of luck.


BR, Joakim R.

New Contributor

Re: [Tutorial] How to replace SSL certificate.

Hey, I am new to Aruba, just landed into at this new job. I see that in ArubaInstant that I can't generate a CSR, so what you are saying is that it is completely ok to run the CSR off of some random linux box and it will still be able to pickup the cert and work? I just want to clarify before I jump in and buy a cert.

Guru Elite

Re: [Tutorial] How to replace SSL certificate.

Yes you can:  http://community.arubanetworks.com/t5/Controller-less-WLANs/How-to-Create-a-Certificate-for-Instant-Captive-Portal-using/ta-p/277025

Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

New Contributor

Re: [Tutorial] How to replace SSL certificate.

This is exactly what I was trying to find. Thanks so much!

New Contributor

How to replace SSL certificate.


We use Aruba Controller with NPS. Our default geotrust ssl sertificate expired two months ago. After that, We uploaded Comodo 3months trial ssl certificate with .crt. This SSL certificate was generated with Aruba CSR. We had no problem on 802.1x authenticaion on clients. After 3 months later, We decided to get multidomain wildcard certificate from Comodo, but we generated CSR request file from another server. After that We tried to upload ssl sertificate as PFX extension, but this certificate was not available to clients. When we tried to upload as .crt extension, we got an error as CSR mismatch (because csr is generated on another server). How can we solve this problem or can you give an advice about this situation.



Guru Elite

Re: How to replace SSL certificate.

Is this for the EAP server certificate or captive portal certificate? It's not clear.

Tim Cappalli | Aruba Security
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
New Contributor

Re: How to replace SSL certificate.

Our certificate is eap server certificate.
Search Airheads
Showing results for 
Search instead for 
Did you mean: