http://mobilesociety.typepad.com/mobile_life/2016/01/wifi-ce...
For example, EAP-TLS, unlike the TLS used in HTTPS, requires a client to provide a X.509 certificate signed by an AP-side trusted authority. This is because people like Jouni Malinen (hostapd/wpa_supplicant), in all their wisdom, decided to spurn RFC 5216 ("While the EAP server SHOULD require peer authentication, this is not mandatory, since there are circumstances...") and completely disallow any and all configuration to disable the client-cert requirement, regardless of any circumstances (such as those behind HTTPS). NYC DoITT is no more equipped to provision X.509 certs for free wifi users than the NYS DMV is to provision X.509 certs for $80 DL/ID card holders (so people can securely prove their identity everywhere).
As trollian stated, Wi-Fi Alliance's "Passpoint" (Hotspot 2.0) does allow for such setups, technically. E.g., the vendor-specific WFA-UNAUTH-TLS version of EAP-TLS does not do client-side authentication at the WPA-level, as per RFC 5216. But WFA-UNAUTH-TLS, even among Passpoint-aware devices, is likely not widely supported.
I'm not convinced that is really true. Sure, some sort of client authentication is technically required, but I think you can configure the authentication server to accept any authentication without compromising the link security. Or you could auto-provision users on first login or something like that depending on what sort of access you want to give.
It this supported anywhere? Hence the mention of HS2.0 and my jab at Jouni. (In Jouni's defense, hostapd has made really good progress on this.)
> Or you could auto-provision users on first login or something like that depending on what sort of access you want to give.
This may be supported by Hotspot 2.0 Release 2 (IEEE 802.11u) Online Sign Up (OSU) Server-Only Authenticated L2 Encryption Network (OSEN). I would like to know if OSEN is usable for this scenario.
> It this supported anywhere?
Yes. FreeRADIUS can do it. The clients don't notice. I've seen it work. The configuration is a bit tricky though. Not sure about hostapds radius server.
I've seen it in place at the Chaos Communication Congress in 2014, I used it with a couple of clients without issues. Not sure what was used or how much effort the configuration was.