Skip to Content.

cat-users - Re: [cat-users] FW: CAT

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


Re: [cat-users] FW: CAT


Chronological Thread 
  • From: "Tom Ivar Myren" <tom.myren AT uninett.no>
  • To: "'Stefan Winter'" <stefan.winter AT restena.lu>, <cat-users AT geant.net>
  • Subject: Re: [cat-users] FW: CAT
  • Date: Thu, 30 Jan 2014 09:10:48 +0100
  • List-archive: <http://mail.geant.net/pipermail/cat-users/>
  • List-id: "The mailing list for users of the eduroam Configuration Assistant Tool \(CAT\)" <cat-users.geant.net>
  • Organization: Uninett AS



> >
> > Of course they have a few cases where users cannot roam, which they fear
> > might increase if CAT cannot force realm into username.
>
> This last part doesn't seem right: you can always configure CAT to use
> anon outer IDs (which the n*do* contain the realm) - and if your ID mgmt
> backend is prepared to handle non-realm usernames anyway, then there is
> no problem. Even users forgetting their realm in the username will be
> routed correctly based on the outer ID.

OK - this means they definitely should use anon outer IDs.

>
> Are we maybe specifically talking Windows Vista/7 built-in PEAP here?

No, but they will of course have some of these clients, and therefore my
previous suggestion would still be wanted.

/Tom

> That is the only place I recall where adding an explicit realm as outer
> ID is not possible, because it's derived from the realm of the inner ID
> instead (stupid as that may be).
>
> Greetings,
>
> Stefan Winter
>
> >
> >
> >
> > And, yes they should change their practice anyway…
> >
> >
> >
> > /Tom
> >
> >
> >
> >
> >
> > From: Alan Buxey
> > [mailto:A.L.M.Buxey AT lboro.ac.uk]
> > Sent: 29. januar 2014 14:05
> > To: Tomasz Wolniewicz;
> > cat-users AT geant.net
> > Subject: Re: [cat-users] FW: CAT
> >
> >
> >
> > I'd the tool can do it then it should do it (imho). Yes, there are issues
> > when user faces the supplicant directly or uses a system not supported but
> > that is true for other tools too... and experience shows that most users
> > seem to just run the setup tool again. ... and again. . Whenever they
> > face a
> > issue (which is a big problem when they are at a remote site and think
> > they
> > can use setup there because it's eduroam still .... No matter what the
> > text
> > on the sites setup pages says). User education is a must... but engaging
> > with them in this current phase of technology and IT is problematic.
> >
> > Alan
> >
>
>
> --
> Stefan WINTER
> Ingenieur de Recherche
> Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
> de la Recherche
> 6, rue Richard Coudenhove-Kalergi
> L-1359 Luxembourg
>
> Tel: +352 424409 1
> Fax: +352 422473
>
> PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
> recipient's key is known to me
>
> http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC6
> 6






Archive powered by MHonArc 2.6.19.

Top of Page