cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: Jinse Paul <address@concealed>, "address@concealed" <address@concealed>
- Subject: Re: [[cat-users]] Certificate Deployment
- Date: Mon, 2 Jul 2018 16:30:17 +0200
Hi,
> You guys may aware of that behaviour,
It's the core reason of existence of CAT :-)
> do you think whether CAT or a
> public CA is the best and easiest way to overcome this ? Or any other
> suggestions also please welcome.
A public CA does not win you anything: the user will still have to mark
that particular CA certificate as trusted for Enterprise Wi-Fi purposes;
merely the act of installing the certificate itself is economised.
Note that your described workflow in your original mail already makes a
flawed assumption: devices can not install the trust root (CA) because
it is not part of the EAP conversation - only server cert and possibly
intermediates are typically transferred. The devices may or may not
permanently save the *server* certificate, which is not the basis of trust.
You subject your users to a TOFU (trust on first use) issue - if they
are fooled during their first connection by an attacker, they will trust
the adversary, not you, in the future.
And even if they install the correct certificate, the trust goes away as
soon as you renew your certificate; you avoid that by proper
installation of the CA instead.
And yes, CAT is one of the tools which do that for you :-)
Greetings,
Stefan Winter
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] Certificate Deployment,
Jinse Paul, 07/02/2018
- Re: [[cat-users]] Certificate Deployment, Stefan Winter, 07/02/2018
Archive powered by MHonArc 2.6.19+.
