Do we know how many/share of insts use commercial CAs for their EAP servers?
Is the change (becoming) “official”? I.e. vote in CA/B Forum? Announcement from Google that they confirmed do it anyway? Early canary build with this included? No visible/tangible changes to Chrome seen.
For completeness sake: ACME works even when server does not have internet connectivity or an open HTTP/S port: dns-01 validation can be automated.
cert renewals are going to be frequent and complicated; possibly driving more admins to as-a-service solutions
documentation can help; not much more can be done
scripting on FreeRADIUS possible to some extent…? Like, LetsEncrypt support included in the distribution; if you really want a commercial cert - run that script regularly and you’re good. Alan to investigate if this can be done
IETF / EAP-FIDO updates
RADIUS/TLS changes are substantial and needs to be cross-checked