Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Release of CAT-2.0.0-beta1

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Release of CAT-2.0.0-beta1


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Martin Pauly <address@concealed>, address@concealed
  • Cc: address@concealed
  • Subject: Re: [[cat-users]] Release of CAT-2.0.0-beta1
  • Date: Mon, 27 Aug 2018 15:12:57 +0200

Hello,

also to you a big Thank You for trying this out!

>> So the time to test this in a pre-production stage is NOW :-)
> a quick check on Windows 10 shows that the basics do work.
>
> But what about the new features:
>
> 1. Code/Profile Signing
> Windows 10 complained again that this program lacks a recognized
> publisher cert,
> I had to click "Trotzdem ausführen" (Execute despite of lacking cert).
> AFAIR, code signing had been announced as one of the upcoming CAT 2.0
> improvements
> on the German mailing list.

The production instance uses a Extened Validation Code Signing
certificate which we are constantly monitoring for expiry time, signing
hardware status etc.

On the test instance right now, you are warned because we used an old
non-EV code signing certificate (those trigger the Windows warnings,
non-EV is not good enough these days) which on top of being non-EV is
also expired :-(

My apologies; this is "only" a deployment issue in the test environment.
The production environment does not face this same issue.

If you want to see the real signing certs and the Windows behaviour with
those, I can only suggest you download an installer from another
institution on the current production site (cat.eduroam.org) and launch
it on your system. This will be the behaviour you get once we deploy the
new version in production.

> 2. Built-In sanity check of username
> Me and others had a bit of trouble getting the username right during
> the Windows install. No big deal, but Tomasz Wolniewicz wrote:
>>   in eduroam CAT 2.0 we will have an option to either just nag the user
>> about missing realm or even to pre-fill the realm with a configured
>> string.
>
> Stefan Winter wrote today:
>> The upcoming version 2.0 allows the administrator to decide if
>> a) such a hint should be provided to the user (input box is prefilled
>> with realm ending) and/or
>> b) the installer should actively verify the presence of a realm name in
>> the input, and refuse to continue installation if not.
>>
>> Both of these are then checkboxes on the Profile level.
>
> So for 2., we will have to edit our profile first,right?

Yes, those are checkboxes you have to set as an admin. They are by
default off (which is then producing the identical bahviour that version
1.1 did).

> (presumably not yet productive for German admins)

Yes and no. Your data has been imported and you can edit your profile
*if* your eduGAIN/DFN-AAI/social account is linked to your institution.

During the merge of the German and World datasets, the table that saves
the "ownership" data of which person administers which institution has
been omitted, for two reasons:

- the user identifiers are personal data, and there was no sufficient
argument to transfer this data
- the data is actually useless because eduGAIN/DFN-AAI are
privacy-preserving by default themselves: even when you log into both
the old and the new website with the same actual identifiers, the
websites only get to see a per-website opaque user identifier. I.e. it
is not possible to recognise "you" across the sites, and the mapping fails.

So, as of today, the German IdPs in the test system have no owners. This
is known also to the personnel at DFN.

That being said, DFN personnel of course has NRO-level access to CAT,
also on this test site, and can send institution admnistrator
invitations to re-establish the mapping. You will have to contact DFN to
get that done for you, and then you can edit your profile.

Note that it *will* (well, "should" - we haven't ever done it but
nothing seems to prevent it) be possible to preserve the ownership
mapping between test and prod later on; they are both sub-services under
one SAML SP (eduroam Service Provider Proxy) so if DFN enables your
access to the system now in the test phase you shouldn't need to re-do
that again later on during production time.

Greetings,

Stefan Winter

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page