That is all handled by your radius server, if I understood your question correct. The WLC will simply forward the authentication request to the radius.
I suggest using correctly signed certificates on the radius, then the client should not connect to a spoofed ssid with spoofed radius server (which shouldn't have the same hostname/certificate combination). This of course requires the enabled "Validate certificate" setting, something that is often disabled on Android (but enabled by default on Windows or Apple OS).