We just rolled this out using a linux radius server & external CA.
Pushed out the root & intermediate CA certs with a configuration policy
beforehand. Then used a script to download, import & assign the unique
certs to the target SSID. Used the seria...