Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Admin wird auf cat.eduroam.org als "Unknown User" angezeigt

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Admin wird auf cat.eduroam.org als "Unknown User" angezeigt


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: "Schmid, Martin" <address@concealed>, address@concealed
  • Subject: Re: [[cat-users]] Admin wird auf cat.eduroam.org als "Unknown User" angezeigt
  • Date: Fri, 5 Oct 2018 11:13:49 +0200

Hello,

>  darf ich hier bitte die Frage stellen: Warum werde ich als
> Administrator als Unknown User auf cat.eduroam.org geführt werden,
> obwohl unser IdP die vom SP angeforderten Attribute wie display name,
> eduPersonTargetID und email schickt.

For the benefit of the list, I'll answer in English.

eduroam CAT does not perform user authentication on its own, we are
using a proxy that authenticates all eduroam Operations Support
Services, the "eduroam SP Proxy".

That proxy receives your user attributes, including the opaque user
identifier (NameID, or eduPersonTargetedId). The proxy also receives
your real name and any other attributes your IdP sends.

The proxy then chooses which of these supplementary attributes (in
addition to the NameID equivalent) it trusts and stores in its own
session database. The rule on that server is: only manually vetted
information is stored. The effect is that users with the NRO privilege
get their name saved (the name is verified by a human against the
information in the eduroam operations database). For any other user, we
do not have authoritative information on the real names of people, so
the information is considered untrusted and discarded.

I am not exactly a fan of that treatment myself. In its defence though,
there is a reason to be that cautious: amongst others, we allow social
ID providers such as Google as authentication source. Anyone can enter
any information they like about themselves at these sources. So the real
name could be tampered with to "impersonate" (only on visual inspection
of course, since the NameID is different) a NRO admin or anyone else the
user feels like.

Of course one natural way forward would be to consider eduGAIN R&E
institutions(*) as more trusted than anyone else and take their
assertions on the real name as trusted; while still discarding others.
I'm hoping that something along those lines will be implemented in the
eduroam SP proxy at some point - but hoping is all I can do. It's not my
product.

I hope this explains the situation sufficiently.

Greetings,

Stefan Winter

(*) note that I didn't write "eduGAIN" without this qualifier. Some
social providers are actually eduGAIN IdPs. The eduroam SP proxy for
example has the "GitHub via eduTEAMS Identity Hub"; there would also be
a "Google via eduTEAMS Identity Hub" but we have manually removed that
on the SP proxy because it clashes with the "direct" Google login in the
Social tab.
Trusting eduGAIN in its entirety defeats the purpose of excluding
"unvetted social providers".

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page