Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Problems with Android Client after certificate update

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Problems with Android Client after certificate update


Chronological Thread 
  • From: Daniele Albrizio <albrizio AT units.it>
  • To: Stefan Winter <stefan.winter AT restena.lu>, Daniele Albrizio <daniele AT albrizio.it>, Michele de Varda <michele.devarda AT unimi.it>
  • Cc: Claudio Lori <claudio.lori AT unimi.it>, cat-users AT geant.net
  • Subject: Re: [[cat-users]] Problems with Android Client after certificate update
  • Date: Tue, 14 Feb 2017 10:17:18 +0100
  • Organization: University of Trieste

On 14/02/2017 09:02, Stefan Winter wrote:
Hello,

Android without CAT connects to Eduroam no matter what certificates
Radius server presented them and this is very unsecure.

That's correct. "It works if I turn off all security" only demonstrates
flawed thinking, not proper operation.

What about clients using eduroam CAT? Did you insert the server
certificate too, in old eduroam CAT configuration for your institution?
If yes, this may be the problem: clients may not trust the new
certificate because they are clamped to the old. Suggestion for the
future is trying to use only the trust anchor needed. That is the
intermediate ca certificate.

Here Daniele is slightly wrong: the trust anchor is always the /root/
certificate.

Thanks for spotting this.

[...]

Android connection attempts will fail: Android does not allow the app to
install the intermediate together with the root and relies on getting
the intermediate during authentication time.

Wow, bright, now some things (happening in my institution too) are clearer in my mind. :D Thanks.

[...]

--
Daniele ALBRIZIO -
daniele.albrizio AT units.it
Tel. +39-040.558.3319
UNIVERSITY OF TRIESTE - Network Services
Unita' di Staff Reti di Ateneo
via Alfonso Valerio, 12 I-34127 Trieste, Italy

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature




Archive powered by MHonArc 2.6.19.

Top of Page