Some browser keep the HTTPS connection active, and you may need to close the browser tab and reopen, or even quit and restart the browser.
From the CLI, you can verify which certificate is active/in use:
IAP-303H-1a:68# show cert assignment
cert assignment
---------------
Application Cert type Cert name
------------------------ ------------------------- -----------------------
captive-portal ServerCert instant.nl.arubalab.com
ui ServerCert instant.nl.arubalab.com
With 'show cert all' you can check the contents of the certificate, like the expiration date. If you still see another certificate, I would first reboot the AP, and open a TAC case if the issue is still there.
In some networks there is 'SSL inspection' that breaks the HTTPS traffic by spoofing certificates; but those should be easily detectable by checking the issuer which is different from the actual certificate.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Dec 16, 2024 06:45 AM
From: mrccbu
Subject: New Captive Portal/UI certificate installed, still using old one
Hi,
I believe this is an old, solved problem, but the way we did it last time doesn't appear to be available to us anymore.
We are using 325's in an Instant configuration. New cert. has been uploaded, and assigned to both the WebUI, and the Captive Portal, but when I check in a browser the old certificate is still active.
What we used to do is switch to the old UI, then back again, but that option doesn't seem to be available any more, that I can find.
The firmware we are running is:
8.9.0.2_83074 (Digitally Signed - Production Build)
------------------------------
Howard
------------------------------