A municipality is rolling out EAP-TLS for thousands of city and school devices. Which CA and certificate-lifecycle consideration is most important at that scale?
Select an answer to reveal the explanation.
Short Explanation
EAP-TLS at city scale is a PKI problem wearing a Wi-Fi hat. Enrollment, renewal, and revocation have to work for real—not one golden cert on a USB stick. Self-signed portal art and intentional expiry earn tickets, not trust.
Full Explanation
Certificate-based WLAN authentication depends on a trustworthy public-key infrastructure. Municipal deployments need automated or well-managed enrollment, renewal, and revocation so compromised or departed devices lose access. Shared exported certificates, self-signed captive-portal material, and intentional expiry undermine authentication integrity and operational stability.