I have about 60 Macs in the enterprise, trying to authenticate to a RADIUS server using EAP-TLS.
Right now we're using a HEAVILY manual process where we have to install both a user and a computer certificate, and even then, the authentication fails from time to time. I want something as pushbutton as possible, as this is the #1 Mac-related challenge we're being asked to resolve right now.
What are the best practices in the space? Is there a specific way that the RADIUS server should be configured? Do I need separate certificate structures to authenticate Macs? I've read things that hint at both, but nothing definitive.