The internal authentication server for certificate-based authentication requires you to install a certificate on the wireless controller. A default self-signed server certificate is installed on the wireless controller. However, NETGEAR strongly recommends that you replace this default certificate with a custom certificate issued for your site or domain by a trusted certificate authority (CA).
To obtain a security certificate for the wireless controller, generate and submit a certificate signing request (CSR) to the CA of your choice. Upon receiving the CA-signed server certificate, install the certificate from your computer as described in this section. Certificates must be in X.509 PEM format.
To add certificates:
- Open a web browser. In the browser's address field, type the http:// followed by the IP address that you assigned to the wireless controller.
By default, the IP address is 192.168.0.250. If you have not yet assigned another IP address to the wireless controller, type http://192.168.0.250.
The wireless controller's login screen displays. - Enter your user name and password.
If you have not yet personalized your user name and password, enter admin for the user name and password for the password, both in lowercase letters. - Click the Login button.
The wireless controller's web management interface opens and displays the Summary screen. - Select Configuration > System > Certificates.

- Configure the settings as described in the following table:
Setting Description Password Enter the password for wireless controller certificates. Controller Key Click the Browse button, and select the controller key. Controller Certificate Click the Browse button, and select the controller certificate. CA Certificate Click the Browse button, and select the CA certificate. - Click the Apply button.