The X.509 certificates are burned into protected flash on both the access point (AP) and WLC at the factory by Cisco. On the AP, factory installed certificates are called manufacturing installed certificates (MIC).
You must select MIC box to connect AP to WLC.
For Auth for APs
you can add the mac address of APs and check the box Autheriz MIC APs againest auth-list or AAA.
Regards