cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID)
Chronological Thread
- From: IAM David Bantz <db AT alaska.edu>
- To: stefan.winter AT restena.lu
- Cc: cat-users AT lists.geant.org
- Subject: Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID)
- Date: Tue, 16 Oct 2018 09:40:43 -0400
- Authentication-results: prod-mail.geant.net (amavisd-new); dkim=pass (2048-bit key) header.d=alaska-edu.20150623.gappssmtp.com
Yes our network, security and user services groups have heard me describe downsides of simple native supplicant provided domain-qualified username and password:
both the MiM security risk, and the privacy concern of full username in outer identity. They acknowledge greater security and privacy of CAT-configured supplicants, but those are viewed as trade-offs with ease of use.
David Bantz
U Alaska
On Tue, Oct 16, 2018 at 2:35 AM Stefan Winter <stefan.winter AT restena.lu> wrote:
...there is no need for a test SSID.... you don't need a test /network/. You
just need to test /devices/ on the existing network...
...have you talked to your network and user support groups about
the very real-life risk of credential theft when not verifying that the
username and password are sent to the actual, authorised authentication
server?
- [[cat-users]] installers for use on eduroam-test (local non-production SSID), IAM David Bantz, 10/12/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Stefan Winter, 10/15/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), IAM David Bantz, 10/15/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Stefan Winter, 10/16/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), IAM David Bantz, 10/16/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Stefan Winter, 10/17/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), IAM David Bantz, 10/17/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Stefan Winter, 10/19/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Martin Pauly, 10/19/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), IAM David Bantz, 10/17/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Stefan Winter, 10/17/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), IAM David Bantz, 10/16/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Stefan Winter, 10/16/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), David Andrus, 10/16/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), IAM David Bantz, 10/15/2018
- Re: [[cat-users]] installers for use on eduroam-test (local non-production SSID), Stefan Winter, 10/15/2018
Archive powered by MHonArc 2.6.19.