There is a Novell LDAP directory what contains all workers.
But the structure is a bit complicated. There are several OUs in the same LDAP directory, so I had to add each OUs to the sites-available/ldap configuration.
I have tested with ldapsearch and the radtest, and the users were found, so it works well.
However It seems to be solved the iOS16 issue. I created a new .mobileconfig with the WPA2-enterprise network and I have added the server cert and attached to it. Now it started to work...
If I add public cert to radius server, the client will trust it automatically or I need to add manually to the client as well?