Orchestration
Go control plane
The Go operations platform coordinates the enrollment workflow and hands managed-device configuration to Jamf Pro.
Systems / Network identity
Passwordless Wi-Fi deployed and maintained across global offices with Linux FreeRADIUS, EAP-TLS, managed device certificates and UniFi enforcement.
Four layers, each with one clear responsibility.
Orchestration
The Go operations platform coordinates the enrollment workflow and hands managed-device configuration to Jamf Pro.
MDM
Jamf Pro distributes the device certificate and Wi-Fi profile, so network identity arrives through device management rather than user setup.
Authentication
I self-hosted and configured FreeRADIUS to validate certificate-backed device identity without a shared Wi-Fi password.
Network operations
I configured and maintained UniFi networking, VPN access, DNS controls and HTTP firewall policies across global offices. UniFi applies each RADIUS access decision.
Sanitized system view
Representative workflow using no certificate, topology or office data.
EAP-TLS / Validate
Review the managed enrollment and enforcement chain before a device is allowed onto the network.
Provisioning
Go platform + Jamf Pro
Enforcement
FreeRADIUS + UniFi
Trust checks
Users connect without entering a shared password. The seamless experience is the visible result of managed identity underneath.
Proof in the build
Jamf Pro distributes both the device certificate and Wi-Fi profile, so managed devices receive network identity without manual user setup.
If device identity cannot be verified, access is rejected rather than guessed.
Proof in the build
FreeRADIUS validates the EAP-TLS identity and UniFi enforces that decision, with no fallback to a shared credential.
Architecture and user experience only, with no topology, certificate profiles, secrets or operational runbooks.