Zero-Touch Hotspot 2.0 Onboarding Fix

Job ID: 39750002

Budget: $250 – $750 USD

I have a Raspberry Pi-based access point broadcasting the SSID “OSU_Welcome_Shop”. hostapd, dnsmasq and FreeRADIUS are all running, HS2.0 / ANQP / OSU / OSEN settings are in place, and the RADIUS server is successfully handling authentication, accounting and user access. The missing piece is the seamless experience: phones and laptops that wander into range never receive the expected Hotspot 2.0 onboarding or provisioning notification. Users still have to open Wi-Fi settings and pick the SSID manually, which defeats the zero-touch goal.

What I need is an expert who can trace where the discovery flow breaks, adjust the hostapd HS2.0 configuration, validate ANQP and OSU server responses, and make sure the correct vendor-specific IE fields and certificates are advertised so that capable devices automatically pop up the “Sign Up / Get Online” dialog—no pre-installed app or profile.

Deliverables
• Updated hostapd, dnsmasq and RADIUS configs (and any supporting files or certificates) that trigger automatic onboarding on standard Hotspot 2.0-capable clients
• A short write-up of what was changed and why, so I can reproduce it on additional units
• A quick test script or command sequence that proves provisioning and EAP exchange succeed end-to-end

Acceptance criteria: placing a fresh iOS or Android phone within range must bring up the native enrollment/provisioning prompt within a few seconds, and the device must complete sign-up and reach the internet without any manual SSID selection.

If you live and breathe HS2.0 beacons, ANQP responses, OSU SSL chains and RADIUS inner/outer identities, I’ll supply SSH access to the Pi and the external OSU web server so we can put this network on autopilot.