cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
Re: [[cat-users]] Imperial College Healthcare NHS Trust possible CAT tool/certificate issue
Chronological Thread
- From: Stefan Winter <address@concealed>
- To: "METODIEV, Mike (IMPERIAL COLLEGE HEALTHCARE NHS TRUST)" <address@concealed>, "address@concealed" <address@concealed>
- Subject: Re: [[cat-users]] Imperial College Healthcare NHS Trust possible CAT tool/certificate issue
- Date: Thu, 21 Jun 2018 10:57:03 +0200
Hello,
> Hi Support team, We have some devices not being able to connect if using
> the cat tool but connect if manually on boarded. Could you please
> advise? Thanks.
That's because your RADIUS server got a new server certificate on 25 May
2018, which is issued from a different cert chain than before (same
root, different intermediate).
You have not updated the CAT with the new CA information; so devices
which do not have the new intermediate in their cert stores, and which
do not get the new intermediate in the EAP conversation from your RADIUS
server, cannot complete the trust chain building.
Your server is "eduroam.imperial.nhs.uk" (this corresponds with the CAT
config), issued by:
CN=AffirmTrust Extended Validation CA - EV1,OU=See
www.affirmtrust.com/repository,O=AffirmTrust,C=CA
Whereas the two CA certs you have configured in CAT are:
1) Intermediate:
Subject: C = US, O = Trend Micro Inc, CN = Trend Micro S2 CA
2) Root:
C = US, O = AffirmTrust, CN = AffirmTrust Commercial
Which appears to be a non-EV cert chain.
What you need to upload to CAT is the following:
1) Intermediate:
https://www.affirmtrust.com/downloads/affirmtrust_certificate_authority_ev1.crt
2) Root:
- as configured already -
You should also send the new intermediate in the EAP conversation on
your RADIUS server.
Note: You have chosen an EV certificate. We have evidence that these
types of certificates are considered invalid for Wi-Fi trust purposes on
Google Chrome devices. If you have specifically problems on Google
Chrome, this may be the root cause of the issue. In that case, the only
way to avoid those is to use a non-EV certificate.
Greetings,
Stefan Winter
>
>
>
> Regards, Mike
>
> Infrastructure Network Manager
>
> 02037048042
>
> 07884132092
>
> address@concealed
>
>
>
> Please note my email is now address@concealed. Please update my
> contact details accordingly. Thanks.
>
> cid:address@concealed
>
>
>
>
>
>
>
> ********************************************************************************************************************
>
> This message may contain confidential information. If you are not the
> intended recipient please inform the
> sender that you have received the message in error before deleting it.
> Please do not disclose, copy or distribute information in this e-mail or
> take any action in relation to its contents. To do so is strictly
> prohibited and may be unlawful. Thank you for your co-operation.
>
> NHSmail is the secure email and directory service available for all NHS
> staff in England and Scotland. NHSmail is approved for exchanging
> patient data and other sensitive information with NHSmail and other
> accredited email services.
>
> For more information and to find out how you can switch,
> https://portal.nhs.net/help/joiningnhsmail
>
> To unsubscribe, send this message:
> mailto:address@concealed?subject=unsubscribe%20cat-users
> Or use the following link:
> https://lists.geant.org/sympa/sigrequest/cat-users
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] Imperial College Healthcare NHS Trust possible CAT tool/certificate issue,
METODIEV, Mike (IMPERIAL COLLEGE HEALTHCARE NHS TRUST), 06/21/2018
- Re: [[cat-users]] Imperial College Healthcare NHS Trust possible CAT tool/certificate issue, Stefan Winter, 06/21/2018
Archive powered by MHonArc 2.6.19+.
