Skip to Content.

cat-users - [cat-users] Multiple CA chains

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


[cat-users] Multiple CA chains


Chronological Thread 
  • From: Daniele Albrizio <albrizio AT univ.trieste.it>
  • To: cat-users AT geant.net
  • Subject: [cat-users] Multiple CA chains
  • Date: Mon, 5 Oct 2015 14:52:42 +0200
  • List-archive: <https://mail.geant.net/mailman/private/cat-users/>
  • List-id: "The mailing list for users of the eduroam Configuration Assistant Tool \(CAT\)" <cat-users.geant.net>
  • Organization: University of Trieste

We, as many, recently changed our upstream CA from Comodo to Digicert.

I asked around for the best way to have a smooth user experience in migrating from one CA to the other and someone told me to install both CA chains so when I change the certificate of the radius server next year many users will already have the new chain in place.

Well, this will not work at least with the Android app: when using the profile I see only the last CA in the profile details. This breaks the current connection.

At this point I have two questions:
1. Is there any other way to migrate smoothly? Is cross-signing possible/suggestable?
2. How many other installers are not designed to handle multiple CA's?


--
Daniele ALBRIZIO -
albrizio AT univ.trieste.it
Tel. +39-040.558.3319
UNIVERSITY OF TRIESTE - Network Services
Unita' di Staff Reti di Ateneo
via Alfonso Valerio, 12 I-34127 Trieste, Italy





Archive powered by MHonArc 2.6.19.

Top of Page