Earlier quoted context omitted.
> * Which EAP? EAP-TLS? EAP-MD5? [0] EAP-MSCHAPv2? Or perhaps EAP-GTC? EAP-TLS ideally. You need a CA infrastructure, a radius server, and a way of doing automated enrolment, revocation and install of client certificates. A lot of work if you haven't already got those parts (though many places already do), but it's fairly hassle free and secure once up and running. For bonus points you can extend 802.11x goodness to…
So, I'm fairly new to this... how would you do automated installation of client certs on: * OS X machines * Android devices * A Nest Thermostat > For bonus points you can extend 802.11x goodness to your wired desktop ports as well. Though, that only works if you have either a Smart or a Managed switch that understands that it needs to tag frames from that port with RADIUS-dictated VLAN tags, right?
Android - MDM (I think the stock google apps MDM can do client Certs and 802.11x network config)
Nest - would not bother; stick on a dedicated standard WPA2 network, segregate from rest of network then leave well alone.
Wired network - yes, you'd need a managed L2 switch (but then you'd need that anyway to trunk multiple tagged vlans to your APs).