Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] CAT installer broken on TTLS PAP

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] CAT installer broken on TTLS PAP


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Tomasz Wolniewicz <address@concealed>, address@concealed, "Cecchini, Paolo" <address@concealed>
  • Subject: Re: [[cat-users]] CAT installer broken on TTLS PAP
  • Date: Tue, 23 Oct 2018 16:25:54 +0200

Hi,

>   So indeed the installer has a problem. We did not think of a situation
> where an IdP would be using inner identifiers like user@staff
> We have been asked many times to add some identifier checks and we have
> two new options on that - the admins now can test if the realm in user's
> identifier matches the realm provided in the configuration or even
> prefill the username field with "@realm". With no options set, we still
> run some basic checks like multiple @ signs or a dot immediately after @
> or no dot in the realm part. This last test causes the error in Paolo's
> case. It looks like we have no choice but to drop this one test as it
> may be doing more harm than good.

Just for the sake of making an argument, I'd like to point out that
something@staff is not a valid user identifier in the sense of the
IETF's "Network Access Identifier (NAI)" RFC. Nor is something with two
@@ signs in it or an @. .

If this kind of identifier is used /without/ enabling outer identity
with a correct NAI, it leads to actual breakage when roaming. I'm
assuming that this IdP has thus turned on outer identities, making this
internal use "okay".

So, I think in general we have a point in testing for these conditions.
But since reality shows us that these identifiers are in actual
deployment, and our sense for standards-correctness is getting in the
way of real deployments, I'm okay with removing the check.

Greetings,

Stefan

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page