cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Tomasz Wolniewicz <twoln AT umk.pl>
- To: David Andrus <david_andrus AT byu.edu>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Subject: Re: [[cat-users]] CAT installer broken on TTLS PAP
- Date: Tue, 23 Oct 2018 18:02:44 +0200
- Autocrypt: addr=twoln AT umk.pl; prefer-encrypt=mutual; keydata= xsBNBEvhYBEBCADIlSk8hnUtSfZ1hLbuqiUxTiBtm65lM6OlxjYnWEsH/boOsVS/WdFZebwK 53eg280UcX9VDjFjy5rimsknCvxabnxk13AF//t9mN9tq5MmIkIcRIpLrtqc8Q0s0E84cNzB bDMtRzAd7JUTmKyAnkKE9i2R9FJKzeR9TTeKtBdgXHtUKPHPGOdxUUv8UWKxsj9AYi2CgN98 jiWLx6lTIpaWegWxIyih7WUKSf43Bpi6wFxhfOxteLyQUpIlGg4CasTVGpFsha8KzlupXOLG Tl3hXtQFWvE0tl1GidvTyuQlOzsZ1vjTNEzI25VTkOIgP4IYcWSkP74p/a239ZcTOHhZABEB AAHNIFRvbWFzeiBXb2xuaWV3aWN6IDx0d29sbkB1bWsucGw+wsB4BBMBAgAiBQJL4WARAhsD BgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRA8PEwxkb+lPgkeB/9NAGlmopLel6EEDFz2 ra3KLBx8kXT3G1K/YYyrjDwNjCkAmm0evzQx8g9vPX2OzvE6Ai2Xi9hPd2K/ShPFPcgJzzjr h9H1XYfBb2N/tRwN9tb4XO5i9Tsa4jP+SG8h2yQY57QOeFy16joDmIZiZrAEIGpqqSV24PrX FSo2d1E4dMswqDXlEYk9hwbdW9H4zOQrnDZeRlRx/RW/cmWTd8r5C12dKhlT/D/fBkL3eYT7 rnjHtS+ArnMUsxu2Z/q6bmxqRyv4Vn4pR0n699iLa0ol2hWeQJFaZyTA7JksW8zWu/Zasd9K Dw3jM59vs/SXVdG8pMexAzH5jmEEAgwYwUbVzsBNBEvhYBEBCACgAz/z7VTnCsPSBUrjCLyS j+eRtr2tQzSU48Qa5hOcIxAKQJQNgOOqs0Mq9fT9lV+OttaYyKtijt1+G2dVMETVFkdZmM0c g8pVJp398993v89U/iwjfvNoqCM/9z312Poha/oL/EOk+gWYxZbyQ18SY69va2WHr6Pl3bzR 6BQpb86W85MreQ2lxd76b6BgjOXA/b39YyU/fMeFQd+wDpT3K1fUr89dYRnyzQIxTBSPOMLQ ShHKc/S8dStbNlLNcnaiyBOsH4A7b6IizQGqyVHBeL7u05X0/ZVdEIgsO3NmQouqY0/WjBdV qg4EsI1VvvgwXKWafP1MryLy4ZcnNjQZABEBAAHCwF8EGAECAAkFAkvhYBECGwwACgkQPDxM MZG/pT6lUQf8DC3i15okq3VycbpTYuH6f1lQkqanMS0z4z8F6xtCeXq0DBFk0ZzAU/mCwc3V PdUVGtRKGjouSAB1HDeTvAth1vY0oOJG3kXBwkcui3QxM3sxksNCRLLwcZVnsK9rt6UVp5aG qBwKf44BSApGyHNuKDhCfMCQHueqlfhJYfXocw6KDObvTkwygHLmw93ohV66v26yNvGo6+q2 qTDykGyuicACPDTyJTWFh2IwwZFAdzcc7St8aKkXFk0zWvoriWHeTLUnuFw7HN640IJkG74a 4NGco2yPc7Cz6q59rgE9xydOOXRdmnfiuJu0kQvQocD1rVLjW3qXdnxPd2/FhO4vWg==
- Openpgp: preference=signencrypt
Hi David, I think you may have a problem with your configuration. From what I could test both reams - onboard.byu.edu and byu.edu are correctly routed to your RADIUS server. The server name CN is onboard.byu.edu but this is just a name and is not used for routing in any way. You ask your users to enter netid AT byu.edu as their identifier
and you have set the realm value to be onboard.byu.edu. Finally
you only support one EAP type - PEAP-MSCHAPv2. In addition to that
you have unset the anonymous identity support. These settings mean that the realm value is not used in any
way, the outer identity is set the same as the inner, therefore
users actually expose their real identity to all eduroam sites.
The realm setting would be used if you had the anonymous outer
identity set. If you set the realm value to byu.edu and set realm checks (or even realm prefill) then you will be sure that your users will be forced to input a correct form of the identifier to Windows and Linux installers (with Apple we cannot do much as the identifier is entered into the local system prompt and we cannot control that). I would also suggest that you enable the anonymous outer identity. As far as I can tell, the current checks of CAT can be applied to
your situation, just fix the config. Tomasz
W dniu 23.10.2018 o 17:27, David Andrus
pisze:
Is it possible to make the realm check configurable? Rather than just on/off let us determine what the check should be. The realm check for our institution requires “@onboard.byu.edu” (which is the URL for our RADIUS server) however we only actually require “@byu.edu” to make life a little easier for our users and the way we’re currently set up @onboard.byu.edu won’t work from on-campus. I’d like to enable the realm check and/or have the prefill option checked, but as currently implemented it won’t work for us.
-- David Andrus Network Product Manager Brigham Young University O: (801)422-0969 C: (385)312-7414
From:
cat-users-request AT lists.geant.org
<cat-users-request AT lists.geant.org>
On Behalf Of Stefan Winter
Hello,
To unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users -- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uczelniane Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576 |
- [[cat-users]] CAT installer broken on TTLS PAP, Paolo Cecchini, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Stefan Winter, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Alberto Martínez, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Alberto Martínez, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Stefan Winter, 10/23/2018
- RE: [[cat-users]] CAT installer broken on TTLS PAP, David Andrus, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, David Andrus, 10/23/2018
- RE: [[cat-users]] CAT installer broken on TTLS PAP, David Andrus, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Stefan Winter, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Alberto Martínez, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/24/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Zenon Mousmoulas, 10/24/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/24/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Stefan Winter, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/23/2018
- Re: [[cat-users]] CAT installer broken on TTLS PAP, Tomasz Wolniewicz, 10/23/2018
Archive powered by MHonArc 2.6.19.