We had Aruba ClearPass engineering customize a QuickConnect profile for us that would:
1.) configure the open network in addition to the wpa2 network, but move it to secondary under the wpa2 network, and
2.) configure the open network with auto-join disabled
This fixed the issue you describe for iOS and OSX devices "service hopping" back to the open network after having been there before.
I've begged Aruba to bake in the above functionality into the online QuickConnect packaging tool, but they have yet to do so. Perhaps if you guess press them, too, they'll stop thinking this benefits only OSU. :)
- Ryan -