We're using Freeradius as our AAA for our 802.1x authentication and currently have a self-signed certificate that works fine on iOS/Android/Chromebook/Linux/MacOS devices, and works for a short time on Windows devices. To resolve the Windows device issue we need to change up to a real certificate - the catch is we need one from a root CA that pre-exists in Windows so that the devices can validate it without needing to connect to the internet. Has anyone out there had this combination of technologies working, and which CA did you choose to get the certificate from that works?