Regarding the AP/client identification, this is the reason I suggested in an earlier email,
https://mailarchive.ietf.org/
arch/msg/captive-portals/ RPwEIuLlW6ZSLmEyaqfxgDrF88Q
"
Posting to the create_href:
POST http://<server>/capport/
sessions (Accept: application/json) { "identity": "<USERNAME>"}
…
The USERNAME could be DHCP option-12 value or MAC address or ?"
I didn’t know exactly what this identity should be. Maybe multiple identity options are useful.
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature