We're a small office and have a Cisco Aironet 1250 access point set to WPA-PSK. Now that we've deployed Active Directory I'd like start authenticating my users via radius instead of a PSK.
To this end I've installed NPS on my SBS 2011 server. The WiFi clients are some company-laptops, some personal iPhones, iPads, Android phones, etc. I.e. a mix of all kinds of devices, not all joined to the domain.
It appears that all authentication methods that involve radius that the Aironet supports require some kind of PKI infrastructure. I managed to easily configure our Cisco ASA 5505 to authenticate IPSEC VPN clients against the same radius server, but can't figure out how to set up the Aironet. Do I really need to install my NPS-server's cert on all those devices, like I've seen some people suggest?