I have a test setup of PacketFence working now. I need some advice on server certificates. Windows tries to validate the certificate by default, so I can only get a connection to work if I turn off validation.  I'm trying to understand what the best practice is for our users, some of whom may be guests. I'm thinking, either...

- use our wildcard certificate from Network Solutions -- this doesn't work too well for 802.1x, is this correct?

- have the users turn off certificate validation

- have the user install the root CA from the PF server

What is our best option?

