Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] CAT installer broken on TTLS PAP

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] CAT installer broken on TTLS PAP


Chronological Thread 
  • From: Tomasz Wolniewicz <twoln AT umk.pl>
  • To: cat-users AT lists.geant.org, "Cecchini, Paolo" <paolo.cecchini AT uniurb.it>
  • Subject: Re: [[cat-users]] CAT installer broken on TTLS PAP
  • Date: Tue, 23 Oct 2018 15:53:36 +0200
  • Openpgp: preference=signencrypt

Hi,
  So indeed the installer has a problem. We did not think of a situation
where an IdP would be using inner identifiers like user@staff
We have been asked many times to add some identifier checks and we have
two new options on that - the admins now can test if the realm in user's
identifier matches the realm provided in the configuration or even
prefill the username field with "@realm". With no options set, we still
run some basic checks like multiple @ signs or a dot immediately after @
or no dot in the realm part. This last test causes the error in Paolo's
case. It looks like we have no choice but to drop this one test as it
may be doing more harm than good.

Cheers
Tomasz


W dniu 23.10.2018 o 13:48, Tomasz Wolniewicz pisze:
> It seems that you are entering paolo.ceccini@staff, CAT was set by the
> IdP admin to check for correctness of the user identifier and it
> assumes that the domain name bus have at least two components, so it
> finds you identifier as incorrect.
> Yours
> Tomasz

--
Tomasz Wolniewicz
twoln AT umk.pl http://www.home.umk.pl/~twoln

Uczelniane Centrum Informatyczne Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University,
pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576


Attachment: smime.p7s
Description: Kryptograficzna sygnatura S/MIME




Archive powered by MHonArc 2.6.19.

Top of Page