In addition to the advice to use an internal CA for the RADIUS EAP certificate, you should use EAP-TLS with client certificates and use some kind of provisioning toolings like an MDM or ClearPass Onboard to get your root CA pushed to the clients, and get the clients securely configured.
Starting with Android 11, Google is enforcing secure connections (which is good) and that requires the certificates to be in place, and that is unfortunately not so simple to do. But at least it prevents end-users from configuring 'Do not validate certificate' and create an insecure setup.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------