Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] "manual" installation instructions

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] "manual" installation instructions


Chronological Thread  
  • From: Tomasz Wolniewicz <address@concealed>
  • To: address@concealed, address@concealed
  • Subject: Re: [[cat-users]] "manual" installation instructions
  • Date: Mon, 5 Nov 2018 22:59:03 +0100

Hi David,

  it could be said that you came to the wrong address. People are on this list precisely for the reason of avoiding manual configurations. There is no way that you can force the users to follow instructions even if they are very precise, we have created CAT to make this manageable.

I think that the institutions advertising insecure configurations are unaware of the risk for the users and tempted by the ease of the insecure configuration. In fact advertising an insecure configuration violates eduroam policy, that requires that all partners provide secure end-end authentication methods.  National eduroam operators should talk to these institutions and explain why they should stop doing that.

Cheers

Tomasz



W dniu 05.11.2018 o 22:47, IAM David Bantz pisze:
I've attempted to find institutions' instructions for manually configuring eduroam supplicants (because I have been charged to provide alternatives to present to users in addition to using CAT installers). I don't know whether I should be surprised, but essentially all instances I found omit designating the authentication service and verifying trust of the certificate it presents. It will be a little hard to maintain a firm stance for locking down these configurations if folks can point to other prestigious institutions that offer a simple "enter your netID and password" and click "automatically connect" as a way of configuring eduroam on their devices. 

Can anyone point me to detailed manual eduroam configuration instructions (particularly for Windows 10, as our CAT installer is failing to enable connecting with a certificate trust issue described in other posts)?

Have there been cases "in the wild" of fake eduroam SSIDs or MiM capturing users' credentials from insecurely configured supplicants? An example will likely carry more weight than only a technically possible risk.

Why are institutions advertising unsecured configurations? 

Thank you,

David Bantz
U Alaska
To unsubscribe, send this message: mailto:address@concealed?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users
-- 
Tomasz Wolniewicz    
          address@concealed        http://www.home.umk.pl/~twoln

Uczelniane Centrum Informatyczne   Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika     Nicolaus Copernicus University,
pl. Rapackiego 1, Torun               pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750     fax: +48-56-622-1850       tel kom.: +48-693-032-576



Archive powered by MHonArc 2.6.19+.

Top of Page