Comment Speaking of Certs - iOS sucks for WPA-Enterprise (Score 1) 6
I overhauled my corporate WiFi and implemented PEAP-CHAPv2 for one SSID so that users can put their Windows Domain user/pass into WiFi, instead of a shared WiFi password. I know - PEAP-TLS would be better, but this one SSID is just for staff BYOD phones so un-managed devices - and managing per-user certs on un-managed devices is like pulling teeth. I just give them DHCP and Internet access and some Internet DNS and everyone is happy.
So anyways for the PEAP cert I use Let's Encrypt in conjunction with my domain. On Android users can use System Certificates and validate the domain and they aren't prompted to trust the PEAP cert - Android does validation instead - the user just has to add our domain to their settings for validation. It's great!
But iOS devices are simply horrible. You don't have that validation option. Users have to get a warning to trust the certificate. They have to view it and see that it is for our corporate domain and signed by Let's Encrypt, but that's asking a lot from non-tech users. It's horrible. But it gets worse. Every month when I refresh the cert - they have to re-trust all over again. Android phones are completely unfazed by the certificate refresh. I wish iPhones were better for WPA-Corporate, but they suck big hairy donkey balls. I love their hardware (for the most part), but their software stack is too dumb in many areas.
So anyways for the PEAP cert I use Let's Encrypt in conjunction with my domain. On Android users can use System Certificates and validate the domain and they aren't prompted to trust the PEAP cert - Android does validation instead - the user just has to add our domain to their settings for validation. It's great!
But iOS devices are simply horrible. You don't have that validation option. Users have to get a warning to trust the certificate. They have to view it and see that it is for our corporate domain and signed by Let's Encrypt, but that's asking a lot from non-tech users. It's horrible. But it gets worse. Every month when I refresh the cert - they have to re-trust all over again. Android phones are completely unfazed by the certificate refresh. I wish iPhones were better for WPA-Corporate, but they suck big hairy donkey balls. I love their hardware (for the most part), but their software stack is too dumb in many areas.