For which kind of devices do you want to implement this? And how do they connect? As you are first talking about MX appliances, but then you mention other vendors like Cisco WLC, Aruba and also HSNM. Is this in fact about Meraki MR wireless?
I don't know HSNM, but in general, the authenticator (this could be the MX, the AP, or the controller) does not need a certificate for this. The client gets redirected to a cloud page that presents a public certificate to the client which has to be trusted there.
The only place where the authenticator needs a certificate is when you want to build a tunnel to the cloud-provider and this gets authenticated with a certificate.
But as we don't yet know exactly what you are planning, it is all guessing what you need.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.