We are creating Some Hotspots of our own that IS NOT Connected to our corporate network.
But i have to create a secure way for our devices to connect to those HotSpot Seamsly, in the same way that they do at Corporate Network.
On Corporate , we Have Certificate Based Authentication based on internal Radius Servers. But on HotSpot networks. Internal Radius Server are not available and we dont wish to make Radius Server Public on the Internet.
the idea is to configure the local Certificate Based Authentication (EAP-TLS) on the SSID
The Devices have already a Personal Certificate Issued by our Private CA and Deployed via MDM.
The devices also already trust the whole Chain of that Private CA Root and Subordinates. And are configgured to Join that SSID by authenticating WPA2 Enterprise using it own certificate.
I Dont want to deploy and configure the devices to trust IdenTrust. cause we have already that working configuration on ALL Devices.
My Goal is to replace Identrust Certificate with my own CA Root Chain
and authenticate the devices based on the configuration and certificate that they already have.
I have searched and didnt find a proper documentation for that scenario.
There is a Guide for CSR Generation for the PEM that should be imported on Meraki in replacement of IdenTrust?