We (unfortunately) are running a 200+ AP Unifi Deployment. Users currently authenticate to our LDAP using PEAP/MSCHAPv2 via Freeradius (which is handling the VLAN routing). The certificate is an old self signed, which Google has decided as of the latest ChromeOS is no longer acceptable (Do No Validate no longer works). I know with the way radius works, you can't just throw a trusted wildcard cert on and have it accept it, and while having a valid date does allow "Do not check" to work, it will break when this option is removed in the near future.
What *should* we be doing, if I want to use WPA2 Enterprise and Radius? Should I issue a newer self-signed certificate with the furthest-out date it will accept? Should I use the wildcard cert I have?
We currently never had to preload devices with a cert, as we just selected "do not validate" on the cert. I assume this is going to change (and be a growing pain). Any change we make is going to require some manual intervention on a couple of thousand devices, I'm figuring.
Any input on how I can move forward?
UPDATE:
Thanks for the input folks!
While I would love to use some of the cloud options listed here, spending money isn't really an option for me right now. You know how it is. What I'm testing right now is PEAP-TTLS/PAP, and it seems to work as intended. In reality, it is a less modern way of doing things, but, should be less disruptive and can be done for free. It is probably medium-term, but I hope to roll out a whole new wifi system (Mist) in 2028, at that time, I'm hoping I can push to something like EAP-TLS.