Skip to Content.

cat-users - Re: [cat-users] FW: CAT

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


Re: [cat-users] FW: CAT


Chronological Thread 
  • From: Stefan Winter <stefan.winter AT restena.lu>
  • To: cat-users AT geant.net
  • Subject: Re: [cat-users] FW: CAT
  • Date: Wed, 29 Jan 2014 15:01:49 +0100
  • List-archive: <http://mail.geant.net/pipermail/cat-users/>
  • List-id: "The mailing list for users of the eduroam Configuration Assistant Tool \(CAT\)" <cat-users.geant.net>
  • Openpgp: id=8A39DC66; url=http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Hi,

> Couldn’t the installer both have text saying realm must be part of the
> username and in addition add realm if @ is missing?
>
> At NTNU they do accept just the username locally, partly solved using
> XpressConnect.
>
> Of course they have a few cases where users cannot roam, which they fear
> might increase if CAT cannot force realm into username.

This last part doesn't seem right: you can always configure CAT to use
anon outer IDs (which the n*do* contain the realm) - and if your ID mgmt
backend is prepared to handle non-realm usernames anyway, then there is
no problem. Even users forgetting their realm in the username will be
routed correctly based on the outer ID.

Are we maybe specifically talking Windows Vista/7 built-in PEAP here?
That is the only place I recall where adding an explicit realm as outer
ID is not possible, because it's derived from the realm of the inner ID
instead (stupid as that may be).

Greetings,

Stefan Winter

>
>
>
> And, yes they should change their practice anyway…
>
>
>
> /Tom
>
>
>
>
>
> From: Alan Buxey
> [mailto:A.L.M.Buxey AT lboro.ac.uk]
>
> Sent: 29. januar 2014 14:05
> To: Tomasz Wolniewicz;
> cat-users AT geant.net
> Subject: Re: [cat-users] FW: CAT
>
>
>
> I'd the tool can do it then it should do it (imho). Yes, there are issues
> when user faces the supplicant directly or uses a system not supported but
> that is true for other tools too... and experience shows that most users
> seem to just run the setup tool again. ... and again. . Whenever they face a
> issue (which is a big problem when they are at a remote site and think they
> can use setup there because it's eduroam still .... No matter what the text
> on the sites setup pages says). User education is a must... but engaging
> with them in this current phase of technology and IT is problematic.
>
> Alan
>


--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
6, rue Richard Coudenhove-Kalergi
L-1359 Luxembourg

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0x8A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19.

Top of Page