City laptops already enroll in a managed PKI. Which EAP method best matches that certificate maturity for employee WLAN?
Select an answer to reveal the explanation.
Short Explanation
If the city already hands out real certificates, use them—EAP-TLS is the clean fit. PEAP with just passwords is the spare tire; fine when you must, but not when PKI is ready. Logos and WEP are not authentication.
Full Explanation
EAP-TLS aligns with environments that have mature certificate issuance and device identity, providing mutual authentication without relying on password-based inner methods. PEAP-MSCHAPv2 remains common but is a weaker fit when PKI can support TLS client certificates. Open splash pages and WEP do not provide enterprise-grade 802.1X authentication for managed city endpoints.