cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: IAM David Bantz <address@concealed>, Tomasz Wolniewicz <address@concealed>
- Cc: address@concealed
- Subject: Re: [[cat-users]] "manual" installation instructions
- Date: Tue, 6 Nov 2018 14:49:31 +0100
Hi,
> I found the language below at
> https://www.eduroam.org/wp-content/uploads/2016/05/GN3-12-192_eduroam-policy-service-definition_ver28_26072012.pdf
> but I did not find corresponding language in the U.S. eduroam documents.
Ah, you figured. Sorry, your message was in the moderation queue.
With all the previous said: if one of the samples you found was in
Europe, feel free to let me know off-list where you found such insecure
instructions. We can pester the institution to change those...
Greetings,
Stefan
>
> 6.2.2 eduroam Security Requirements
> The basic security principle that governs the eduroam infrastructure is:
> The security of the user credentials MUST be preserved when
> travelling through the infrastructure, and all partners providing
> the service MUST observe privacy regulations.
> The relevant technical details are listed in the next section.
> The following requirements apply:
> All eduroam participants (OT, confederation members, connected
> institutions in federations) MUST:
> Always provide trustworthy and secure transport of all private
> authentication credentials (i.e. passwords) that are traversing the
> eduroam infrastructure.
> Ensure that user credentials stay securely encrypted end-to-end
> between the user’s personal device and the identity provider when
> traversing the eduroam infrastructure. A rationale for this
> requirement can be found in Appendix A.
> Ensure that eduroam servers and services are maintained according
> to the specified best practices for server build, configuration and
> security, with the purpose of maintaining a generally high level of
> security, and thereby trust in the eduroam Confederation.
> An additional task for Confederation members is to ensure that the
> participating institutions are fully aware of their responsibility
> to establish an appropriate level of security.
> ..
> Appendix A: End-to-end Encryption of User Credentials
> This ensures that no intermediate party, be it an eduroam
> infrastructure operator or external parties, can steal the digital
> identity of an eduroam user. This enables the eduroam service to
> make an important assertion: using eduroam never exposes the
> credentials to anyone in the infrastructure except the home
> institution, which makes sure that the confederation infrastructure
> operators are neither responsible nor liable for password theft.
> Since no AAA infrastructure available today provides end-to-end
> encryption in itself, end-to-end security has to be established by
> the two ends of the authentication chain: the end-user device
> (notebook, PDA, smartphone, tablet, etc.) and the home
> authentication server. This is achieved by using
> mutual-authentication protocols such as EAP-TTLS, PEAP or EAP-TLS.
> Most notably, authentication methods in use by web-redirect portals
> such as PAP do NOT provide end-to-end security.
>
>
>
> > On Nov 5, 2018, at 12:59, Tomasz Wolniewicz <address@concealed
> <mailto:address@concealed>> wrote:
> >
> > advertising an insecure configuration violates eduroam policy,
> that requires that all partners provide secure end-end
> authentication methods
>
> To unsubscribe, send this message:
> mailto:address@concealed?subject=unsubscribe%20cat-users
> Or use the following link:
> https://lists.geant.org/sympa/sigrequest/cat-users
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] "manual" installation instructions,
IAM David Bantz, 11/05/2018
-
Re: [[cat-users]] "manual" installation instructions,
Tomasz Wolniewicz, 11/05/2018
-
Re: [[cat-users]] "manual" installation instructions,
address@concealed, 11/05/2018
-
Re: [[cat-users]] "manual" installation instructions,
IAM David Bantz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Stefan Winter, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Alan Buxey, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Tomasz Wolniewicz, 11/06/2018
- Re: [[cat-users]] "manual" installation instructions, IAM David Bantz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Tomasz Wolniewicz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Alan Buxey, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Stefan Winter, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Alan Buxey, 11/06/2018
- Re: [[cat-users]] "manual" installation instructions, Stefan Winter, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Martin Pauly, 11/07/2018
-
Re: [[cat-users]] "manual" installation instructions,
Per Mejdal Rasmussen, 11/08/2018
- Re: [[cat-users]] "manual" installation instructions, Stefan Winter, 11/09/2018
-
Re: [[cat-users]] "manual" installation instructions,
Per Mejdal Rasmussen, 11/08/2018
-
Re: [[cat-users]] "manual" installation instructions,
IAM David Bantz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
address@concealed, 11/05/2018
-
Re: [[cat-users]] "manual" installation instructions,
Tomasz Wolniewicz, 11/05/2018
Archive powered by MHonArc 2.6.19+.
