These certs are specifically marked 'Radius EAP'. EAP is only negotiated between the wireless client and the Radius Server. If the controller is passing off Radius authentication requests to an internal Radius server, then the controller is acting as the authenticator, and is not part of the EAP negotiation, and therefore these certs would not be used. If the controller is acting as the Radius Server, then these certs would be used.
I spoke to support as well and they also indicated that the factory dummy certs could be deleted if you were using an internal radius server.
John