Skip to Content.
Sympa Menu

cat-users - [cat-users] Server certificate transition in Android

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

[cat-users] Server certificate transition in Android


Chronological Thread 
  • From: Alberto Martínez <alberto_martinez AT deusto.es>
  • To: "cat-users AT geant.net" <cat-users AT geant.net>
  • Subject: [cat-users] Server certificate transition in Android
  • Date: Mon, 14 Sep 2015 13:37:22 +0200
  • Authentication-results: prod-mail.geant.net (amavisd-new); dkim=pass header.i= AT deusto.es
  • List-archive: <http://mail.geant.net/pipermail/cat-users/>
  • List-id: "The mailing list for users of the eduroam Configuration Assistant Tool \(CAT\)" <cat-users.geant.net>

Hi,

Today we changed our RADIUS server certificate from a "trustable" CA to one of our own. Needless to say, without CAT this would have been a nightmare.

What we did was:
1) Upload our CA cert to CAT along the old chain.
2) Send a message to users urging them to reconfigure their devices using CAT (for certificate rollover mostly)
3) Change the RADIUS server certificate

So today is being less stressful than I feared BUT
The Android app (uk.ac.swansea.eduroamcat) does a poor job for the easy transition. Instead of configuring every cert included in the profile it just took the first (the old) path and ignored the other root CA.

Have we done something wrong regarding the CA paths and the app? Is this the expected behaviour? Or is it a bug?

Thank you for the hard work :)
Regards,
Alberto



Archive powered by MHonArc 2.6.19.

Top of Page