Skip to Content.
Sympa Menu

cat-users - Re: [cat-users] Automatic fetch of CAT tools for our institution?

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [cat-users] Automatic fetch of CAT tools for our institution?


Chronological Thread 
  • From: Tomasz Wolniewicz <twoln AT umk.pl>
  • To: Vidar Kværnø Stokke <vidar.stokke AT ntnu.no>, Steve Bohrer <skbohrer AT simons-rock.edu>, "cat-users AT geant.net" <cat-users AT geant.net>
  • Subject: Re: [cat-users] Automatic fetch of CAT tools for our institution?
  • Date: Thu, 05 Jun 2014 15:03:11 +0200
  • List-archive: <http://mail.geant.net/pipermail/cat-users/>
  • List-id: "The mailing list for users of the eduroam Configuration Assistant Tool \(CAT\)" <cat-users.geant.net>

Hi Vidar,
W dniu 2014-06-05 14:56, Vidar Kværnø Stokke pisze:
Generally we would prefer direct access, if only for download statistics. You
could provide just this one address from your local SSID. But there may be
reasons why local provisioning is better.
I really see both sides on this one. We also update a local captive portal on
an SSID so that users can get theirs hands on the CAT-application. But Steve
brings up a point; what about external users/guests?

My main problem is that on an SSID like this "instructions-for-eduroam", I
would like to restrict as much traffic as possible. It is actually no need for my local
users to be able to go on the Internet on this SSID. So basically RFC1918 IPv4
addresses and no routing for them outside my campus network. This means that they will
not be able to go to cat.eduroam.org for eduroam setup.

I think this is the way we will continue to do it. Most external eduroam
users already have their setup in order.
cat.eduroam.org is just one trusted host you would need to provide access to. This would not really lower your security.

What might also interest you is that in 1.1 we are adding a feature of
deleting
a reference to the temporary network, so that users's device do not
automatically reconnect to it in the future. You will just need to specify the
SSID of such a network.

This one is really good. The SSID "instructions-for-eduroam", for instance,
should really be deleted from the device after running the CAT tool. Will it be
possible to delete multiple SSIDs? I also want to delete an SSID I have for guests that
don't have eduroam accounts.
You can specify as many SSIDs as you like, and by the way, we will be also silently removing the eduroam-TKIP profile from Windows, so if someone runs CAT again and this profile is there it will be taken away.

Tomasz

--
Tomasz Wolniewicz

twoln AT umk.pl
http://www.home.umk.pl/~twoln

Uczelniane Centrum Informatyczne Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University,
pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576






Archive powered by MHonArc 2.6.19.

Top of Page