Passpoint and OpenRoaming: The Relationship
Passpoint (also known as Hotspot 2.0 or 802.11u) is the Wi-Fi Alliance standard that lets devices automatically discover networks, evaluate policy, and connect securely before the user does anything. It uses ANQP queries to learn about available networks and supports advanced policy elements such as Roaming Consortium Organization Identifiers (RCOI).
OpenRoaming, managed by the Wireless Broadband Alliance (WBA), takes Passpoint and turns it into a global roaming service. It defines a federation of Identity Providers (IdPs) — such as universities — and Access Network Providers (ANPs) — such as transport operators, airports, cities, and venues. Devices that hold the correct OpenRoaming-enabled Passpoint profile can connect automatically at any participating network.
In short: Passpoint is the car. OpenRoaming is the global highway system with standardized rules, trust, and billing/settlement frameworks (when used commercially).
The university identity (via existing AAA) reaches far beyond campus when Passpoint profiles and RadSec are properly enabled through a dedicated onboarding layer.
How Universities Extend Their Identity
Most universities already have strong identity systems (Entra ID, Okta, campus directories) and RADIUS/AAA infrastructure that powers eduroam or campus Wi-Fi. OpenRoaming lets them reuse that investment outside traditional eduroam venues.
The practical flow for a student looks like this:
- The student receives a Passpoint profile (ideally via a dedicated self-service onboarding flow) that includes the OpenRoaming RCOI and the university’s trusted server certificate information.
- When the student arrives at a participating OpenRoaming venue (train station, airport, city zone), the device uses ANQP to discover the network and matches the RCOI in its profile.
- The venue’s network (ANP) initiates authentication using RadSec — a secure TLS-protected connection — to reach the university’s IdP or a proxy that speaks for it.
- The university authenticates the student using their existing credential or certificate and returns the appropriate authorization decision.
- The student is online with enterprise-grade security, no captive portal, and no new login.
This is especially powerful for universities because students move constantly between campus, home, transport, and other cities. A single profile can keep them connected across that entire journey.
Students experience seamless connectivity from campus networks through public transport and city locations when OpenRoaming is enabled with the right profiles.
The Role of Dedicated Onboarding Platforms
Manually creating and distributing OpenRoaming-capable Passpoint profiles to tens of thousands of student and staff devices is impractical. Native tools and basic MDM often lack the precision needed for the correct RCOIs, NAI realms, and certificate trust anchors that OpenRoaming requires.
A dedicated onboarding and dynamic PKI platform solves this by:
- Guiding users through self-service enrollment over the public internet (before they arrive on campus or when traveling).
- Issuing per-device EAP-TLS certificates and embedding the exact OpenRoaming RCOI(s) the university wants to advertise and honor.
- Supporting the RadSec side — either by acting as a RadSec proxy or by helping configure the university’s existing infrastructure for secure federation peering.
- Handling lifecycle: renewals, updates to federation participation, and revocation when students graduate or lose devices.
The onboarding layer works with — rather than replaces — the university’s existing AAA and identity systems. It supplies the profiles and often the federation connectivity, while the core authorization decisions stay with the systems the university already trusts.
Driving Meaningful Collaboration
OpenRoaming creates natural, high-value partnerships for universities because the benefit is immediate and visible to students and staff.
One of the strongest examples is public transport. Universities can work with local rail, bus, and metro operators to turn major stations and vehicles into OpenRoaming ANPs. A student leaving their residence hall or apartment can stay connected on the journey to campus without switching networks or re-authenticating. The same profile works at the destination airport when they travel for conferences, internships, or visits home.
Other high-impact collaborations include:
- Airports and airlines that students and visiting academics use frequently.
- City or municipal Wi-Fi in areas with high student populations.
- Partner research institutions, libraries, hospitals, and nearby businesses that want to offer convenient access to the university community.
- Conference and event venues that host academic gatherings.
These partnerships are easier to justify than traditional guest Wi-Fi arrangements because the security model is strong (certificate-based or federated authentication with RadSec), the user experience is automatic, and the university retains control over who can connect.
For Technical Teams: Practical Considerations
- Profile configuration: Ensure Passpoint profiles distributed to devices include the WBA OpenRoaming RCOI(s) in addition to any campus-specific RCOIs. Test both discovery and authentication flows.
- RadSec readiness: Your AAA or a dedicated platform must support RadSec (RADIUS over TLS) with proper certificate trust for the WBA/OpenRoaming PKI. Many modern cloud RADIUS services make this straightforward.
- IdP integration: Decide whether the university will act directly as an OpenRoaming IdP or use a proxy/hub. Dedicated onboarding platforms often simplify the proxy route while keeping policy decisions local.
- Fallback and legacy support: Not every venue a student visits will support OpenRoaming. Maintain a clear, low-friction path (such as a secondary onboarding option) for locations that are not yet participating.
- Monitoring and policy: Track authentication success from remote OpenRoaming networks. Use the same policy engine you already have for campus and eduroam to decide what remote users are allowed to do.
- Testing the full journey: Validate end-to-end from a student device at a real transport hub or airport back to the university IdP before wide rollout.
Because profile management and much of the federation connectivity can live in the dedicated onboarding layer, changes to which RCOIs you honor or which partners you add become configuration updates rather than massive device or infrastructure projects.
OpenRoaming turns Passpoint from a campus or local roaming technology into a practical way to extend the university’s identity across the places students and staff actually travel. When combined with a dedicated onboarding platform capable of provisioning the right profiles and supporting RadSec, universities can deliver the kind of seamless, secure connectivity users now expect — from the moment they leave home until they return to campus — while creating valuable collaborations with transport providers, airports, and local partners.
The technology has matured, the federation is growing, and the operational pieces are increasingly accessible through modern onboarding and PKI layers that work alongside the AAA infrastructure universities already own.