Also, the CN typically will be a name that is unique to a single controller. You can use a wildcard cert that could cover multiple controllers. *.
.
If you do not have a wildcard cert, the common name you use should resolve to the L3 Topology IP you used on the controller to create the portal service.
For example the L3 Topology IP may be 10.1.1.1, the cert CN was Controller1.ExtremeNetworks.com, on your DNS server the users of the portal are using, you will need to add a record for Controller1 to map to IP 10.1.1.1...
Let me know if you have any questions.
Doug Hyde
Director, Technical Support / Extreme Networks