Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] id@realm in the "internal" identity mandatory with Windows ?

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] id@realm in the "internal" identity mandatory with Windows ?


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Marc Fradin <address@concealed>, address@concealed
  • Subject: Re: [[cat-users]] id@realm in the "internal" identity mandatory with Windows ?
  • Date: Fri, 24 Aug 2018 08:55:59 +0200

Hello,

> it seems that under Windows (7,10) it is /mandatory /to specify
> id*@realm* in the "internal" identity whereas it is not the case under
> Android or Ios if *anonymous@realm *is set in the profile
>
> in this case, is it not necessary to specify it at the time of
> configuration?

The Windows built-in supplicant behaves like that, yes. We can only
configure it within its own limits, and not change that behaviour.

The root cause is that anon ID configuration in that supplicant only
allows you to specify the local part before the @ - the suffix, which is
required to be there in eduroam, is inferred from the actual inner
identity. Which in turn means the inner identity needs to have the
suffix in it.

An alternative is to enable the EAP type TTLS on your server, and to let
CAT produce TTLS installers - in those, we include our our own EAP
plug-in called GEANTlink which doesn't have such an "interesting"
limitation.

Greetings,

Stefan Winter

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page