cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Tomasz Wolniewicz <twoln AT umk.pl>
- To: Jacques ROGNIN <rognin AT essec.edu>, Stefan Winter <stefan.winter AT restena.lu>
- Cc: cat-users AT geant.net
- Subject: Re: [cat-users] CAT 1.1 Issues
- Date: Thu, 28 May 2015 14:01:04 +0200
- List-archive: <http://mail.geant.net/pipermail/cat-users/>
- List-id: "The mailing list for users of the eduroam Configuration Assistant Tool \(CAT\)" <cat-users.geant.net>
Hmm, are these screen dumps form cat.eduroam.org? They should not look like that. Could you send me the whole window dump? Tomasz W dniu 2015-05-28 o 13:34, Jacques
ROGNIN pisze:
Hello Stephan,
thanks a lot for your help.
I loaded The Root CA cert and the ICA cert to my profile
and it works .
But something else happened during the CAT realm check :
I got a warning message saying :
Testing
from: eduroamTL
dk
elapsed time: 1081 ms. Test FAILED: the request was rejected immediately, without EAP conversation. This is not necessarily an error: if the RADIUS server enforces that outer identities correspond to an existing username, then this result is expected (Note: you could configure a valid outer identity in your profile settings to get past this hurdle). In all other cases, the server appears misconfigured or it is unreachable. So I removed the anonymous user check in my radius
configuration to accept the test with cat-connectivity-test AT essec.fr
as the outer identity.
The next check gave me :
Testing
from: eduroamTL
dk
Connected to frad01.essec.fr.
elapsed time: 3056 ms. Test partially successful: a bidirectional RADIUS conversation with multiple round-trips was carried out, and ended in an Access-Reject as planned. Some properties of the connection attempt were sub-optimal; the list is below. The certificate chain as received in EAP was not sufficient to verify the certificate to the root CA in your profile. It was verified using the intermediate CAs in your profile though. You should consider sending the required intermediate CAs inside the EAP conversation. show server certificate details»I tried to change the server cert , putting the ICA cert
and the server cert in the same file but the radiusd doesn't
accept this.
Do you have an idea ?
Thanks for your help.
Jacques
2015-05-27 20:48 GMT+02:00 Stefan
Winter <stefan.winter AT restena.lu>:
Hello,
You MUST upload the root CA. You MAY upload the intermediate CA(s) - if you don't, your RADIUS server needs to send them during the authentication. There is no reason at all to upload the server certificate; it is presented during the authentication. When using Apple configurator, you need to be cautious. IIRC it doesn't warn you if you add the wrong type of certificate - and the iOS device will simply not check the chain because of missing information, and fall back to "the cert's fingerprint". This "works" in a suboptimal way - but is not proper pre-configuration.
Please check the cert chain configuration first. Greetings, Stefan Winter
Jacques ROGNIN
Jacques ROGNIN
-- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uczelniane Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576 |
- [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/27/2015
- Re: [cat-users] CAT 1.1 Issues, Stefan Winter, 05/27/2015
- Re: [cat-users] CAT 1.1 Issues, Stefan Winter, 05/27/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Tomasz Wolniewicz, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Tomasz Wolniewicz, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Tomasz Wolniewicz, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Tomasz Wolniewicz, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Stefan Winter, 05/29/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Tomasz Wolniewicz, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Tomasz Wolniewicz, 05/28/2015
- Re: [cat-users] CAT 1.1 Issues, Jacques ROGNIN, 05/28/2015
Archive powered by MHonArc 2.6.19.