cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Mischa Diehm <mischa.diehm AT unibas.ch>
- To: Stefan Winter <stefan.winter AT restena.lu>, "cat-users AT geant.net" <cat-users AT geant.net>
- Subject: Re: [cat-users] eduroam not working with El Capitan 10.11 Beta
- Date: Mon, 7 Sep 2015 09:35:33 +0000
- Accept-language: de-DE, en-US, de-CH
- List-archive: <http://mail.geant.net/pipermail/cat-users/>
- List-id: "The mailing list for users of the eduroam Configuration Assistant Tool \(CAT\)" <cat-users.geant.net>
Hi Stefan,
what is the status of this?
Do you think it would also make sense to describe how to configure the server side to be ready for this change plus all the implications for older devices that might need DH < 1024?
Thx,
Mischa
--
Mischa Diehm | Network Operations Center (NOC)
UniBasel | UniRechenZentrum (URZ)
Klingebergstr. 70 | CH-4056 Basel
Tel. +41 61 267 2273 | http://urz.unibas.ch
From: Stefan Winter <stefan.winter AT restena.lu>
Date: Donnerstag, 16. Juli 2015 10:47
To: "cat-users AT geant.net" <cat-users AT geant.net>
Subject: Re: [cat-users] eduroam not working with El Capitan 10.11 Beta
Date: Donnerstag, 16. Juli 2015 10:47
To: "cat-users AT geant.net" <cat-users AT geant.net>
Subject: Re: [cat-users] eduroam not working with El Capitan 10.11 Beta
Hi,
Ah, another round of a vendor obsoleting a crypto parameter. I guessit's reasonable to "do something" as this will help against logjam; onlya bit too drastic to make it a DoS IMHO.
FWIW, I just discovered that Chrome will also get harsh on TLS serverswith <1024 DH soon. Chrome 45 is the target for deprecation of small DHgroups:
So in IEEE 802.1X we are certainly not the only ones impacted by this.
I haven't found an easy way to determine DH group length in eapol_testyet. If someone knows more, I'll be very happy to listen :-)
Greetings,
Stefan Winter
--Stefan WINTERIngenieur de RechercheFondation RESTENA - Réseau Téléinformatique de l'Education Nationale etde la Recherche6, rue Richard Coudenhove-KalergiL-1359 Luxembourg
Tel: +352 424409 1Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if therecipient's key is known to me
- Re: [cat-users] eduroam not working with El Capitan 10.11 Beta, Mischa Diehm, 09/07/2015
- Re: [cat-users] eduroam not working with El Capitan 10.11 Beta, Stefan Winter, 09/07/2015
- Re: [cat-users] eduroam not working with El Capitan 10.11 Beta, A . L . M . Buxey, 09/07/2015
- Re: [cat-users] eduroam not working with El Capitan 10.11 Beta, Mischa Diehm, 09/08/2015
Archive powered by MHonArc 2.6.19.