cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Tomasz Wolniewicz <twoln AT umk.pl>
- To: IAM David Bantz <db AT alaska.edu>, cat-users AT lists.geant.org
- Subject: Re: [[cat-users]] connect failure with Win10 CAT installed profile
- Date: Tue, 30 Oct 2018 21:05:37 +0100
- Autocrypt: addr=twoln AT umk.pl; prefer-encrypt=mutual; keydata= xsBNBEvhYBEBCADIlSk8hnUtSfZ1hLbuqiUxTiBtm65lM6OlxjYnWEsH/boOsVS/WdFZebwK 53eg280UcX9VDjFjy5rimsknCvxabnxk13AF//t9mN9tq5MmIkIcRIpLrtqc8Q0s0E84cNzB bDMtRzAd7JUTmKyAnkKE9i2R9FJKzeR9TTeKtBdgXHtUKPHPGOdxUUv8UWKxsj9AYi2CgN98 jiWLx6lTIpaWegWxIyih7WUKSf43Bpi6wFxhfOxteLyQUpIlGg4CasTVGpFsha8KzlupXOLG Tl3hXtQFWvE0tl1GidvTyuQlOzsZ1vjTNEzI25VTkOIgP4IYcWSkP74p/a239ZcTOHhZABEB AAHNIFRvbWFzeiBXb2xuaWV3aWN6IDx0d29sbkB1bWsucGw+wsB4BBMBAgAiBQJL4WARAhsD BgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRA8PEwxkb+lPgkeB/9NAGlmopLel6EEDFz2 ra3KLBx8kXT3G1K/YYyrjDwNjCkAmm0evzQx8g9vPX2OzvE6Ai2Xi9hPd2K/ShPFPcgJzzjr h9H1XYfBb2N/tRwN9tb4XO5i9Tsa4jP+SG8h2yQY57QOeFy16joDmIZiZrAEIGpqqSV24PrX FSo2d1E4dMswqDXlEYk9hwbdW9H4zOQrnDZeRlRx/RW/cmWTd8r5C12dKhlT/D/fBkL3eYT7 rnjHtS+ArnMUsxu2Z/q6bmxqRyv4Vn4pR0n699iLa0ol2hWeQJFaZyTA7JksW8zWu/Zasd9K Dw3jM59vs/SXVdG8pMexAzH5jmEEAgwYwUbVzsBNBEvhYBEBCACgAz/z7VTnCsPSBUrjCLyS j+eRtr2tQzSU48Qa5hOcIxAKQJQNgOOqs0Mq9fT9lV+OttaYyKtijt1+G2dVMETVFkdZmM0c g8pVJp398993v89U/iwjfvNoqCM/9z312Poha/oL/EOk+gWYxZbyQ18SY69va2WHr6Pl3bzR 6BQpb86W85MreQ2lxd76b6BgjOXA/b39YyU/fMeFQd+wDpT3K1fUr89dYRnyzQIxTBSPOMLQ ShHKc/S8dStbNlLNcnaiyBOsH4A7b6IizQGqyVHBeL7u05X0/ZVdEIgsO3NmQouqY0/WjBdV qg4EsI1VvvgwXKWafP1MryLy4ZcnNjQZABEBAAHCwF8EGAECAAkFAkvhYBECGwwACgkQPDxM MZG/pT6lUQf8DC3i15okq3VycbpTYuH6f1lQkqanMS0z4z8F6xtCeXq0DBFk0ZzAU/mCwc3V PdUVGtRKGjouSAB1HDeTvAth1vY0oOJG3kXBwkcui3QxM3sxksNCRLLwcZVnsK9rt6UVp5aG qBwKf44BSApGyHNuKDhCfMCQHueqlfhJYfXocw6KDObvTkwygHLmw93ohV66v26yNvGo6+q2 qTDykGyuicACPDTyJTWFh2IwwZFAdzcc7St8aKkXFk0zWvoriWHeTLUnuFw7HN640IJkG74a 4NGco2yPc7Cz6q59rgE9xydOOXRdmnfiuJu0kQvQocD1rVLjW3qXdnxPd2/FhO4vWg==
- Openpgp: preference=signencrypt
OK, so this explains a lot. However let me point out that if your users find your University on the production CAT they may want to download the eduroam installers which will just fail for them. I suggest that while you are just experimenting, you delete the production-read flag from your profile, and do the experiments via the admin interface download installers. Doing that will hide your University from standard users and save the frustration. Tomasz
W dniu 30.10.2018 o 20:47, IAM David
Bantz pisze:
Thank you for your response Tomaz.
Our University of Alaska CAT installers are for a new
eduroam deployment with completely new infrastructure - not
existing eduroam deployment.
The new Cisco ISEs do use InCommon certificates with the
AddTrust root CA at the top of the chain.
We're testing on a temporary eduroam-test SSID, which is included as secondary SSID in the CAT installers. As a result, the CAT installers are not expected to
provide a working configuration for our existing eduroam
deployment
(which uses private CA and EAP-TLS) but only the new eduroam-test SSID. (We have not previously used CAT; there are no CAT installers for our currently-deployed eduroam
- that current infrastructure uses on aging home-brew tools
and private CA certificates
for both server and user authentication, which is why we
are excited to move to CAT).
Sorry, I should have made that clear in my post.
And yes, iOS, MacOS and Android devices (at least the
very few we've tested) do connect (and automatically
re-connect) to our eduroam-test SSID, using EAP-PEAP
MSCHAPv2 and the Cisco ISE with AddTrust as the root CA as
configured by their respective CAT installers.
On Tue, Oct 30, 2018 at 11:31 AM Tomasz
Wolniewicz <twoln AT umk.pl> wrote:
Hi David, as far as I can tell, your server certificate has been issued by CN=University of Alaska eduroam CA Root but your profile ships the AddTrust External CA Root so these two do not match. It is therefore great that Windows does not connect but it would be really surprising if Apple devices and Android do. I will contact you off-list and perhaps we could do some more testing. Tomasz
W dniu
30.10.2018 o 19:14, IAM David Bantz pisze:
-- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uczelniane Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576 -- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uczelniane Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576 |
- [[cat-users]] connect failure with Win10 CAT installed profile, IAM David Bantz, 10/30/2018
- Re: [[cat-users]] connect failure with Win10 CAT installed profile, Tomasz Wolniewicz, 10/30/2018
- Re: [[cat-users]] connect failure with Win10 CAT installed profile, IAM David Bantz, 10/30/2018
- Re: [[cat-users]] connect failure with Win10 CAT installed profile, Tomasz Wolniewicz, 10/30/2018
- Re: [[cat-users]] connect failure with Win10 CAT installed profile, IAM David Bantz, 10/30/2018
- <Possible follow-up(s)>
- Re: [[cat-users]] connect failure with Win10 CAT installed profile, Stefan Winter, 10/31/2018
- Re: [[cat-users]] connect failure with Win10 CAT installed profile, IAM David Bantz, 10/31/2018
- Re: [[cat-users]] connect failure with Win10 CAT installed profile, Tomasz Wolniewicz, 10/30/2018
Archive powered by MHonArc 2.6.19.