cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: "Morris, Andi" <amorris AT cardiffmet.ac.uk>
- To: "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Subject: [[cat-users]] SHA1 sunsetting
- Date: Thu, 7 Apr 2016 09:02:23 +0000
- Accept-language: en-GB, en-US
Hi all, Having seen all the issues recently appearing on here regarding SHA1 certificates not being supported I was prompted to check the root certificate that I use on my radius server here for our eduroam install and to my horror I found that it is a SHA1 certificate. It’s a self-signed certificate, and we use eduroamCAT to deploy it to the client devices.
Am I likely to hit the sunsetting issues with this certificate being used to secure radius connections with this certificate?
I see in the cat admin interface that I can add a second certificate to the deployment options. Will that do as it seems and add a second certificate to the setup meaning I can phase out the old certificate over time without having to ask approximately 5000 users to resetup their devices? Is installing two certificates likely to cause any issues with particular devices?
It would be ideal if I could allow freeradius to accept two certificates in parallel so I could phase the old one out, but I can’t imagine this would be possible.
Cheers, Andi
------------------------------------- Andi Morris IT Security Officer T: 02920 205720 --------------------------------------
|
- [[cat-users]] SHA1 sunsetting, Morris, Andi, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, Stefan Winter, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, Zenon Mousmoulas, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, Stefan Winter, 04/07/2016
- RE: [[cat-users]] SHA1 sunsetting, Morris, Andi, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, A . L . M . Buxey, 04/07/2016
- RE: [[cat-users]] SHA1 sunsetting, Morris, Andi, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, Tomasz Wolniewicz, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, Tomasz Wolniewicz, 04/07/2016
- RE: [[cat-users]] SHA1 sunsetting, Morris, Andi, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, A . L . M . Buxey, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, Zenon Mousmoulas, 04/07/2016
- Re: [[cat-users]] SHA1 sunsetting, Stefan Winter, 04/07/2016
Archive powered by MHonArc 2.6.19.