cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: IAM David Bantz <db AT alaska.edu>
- To: stefan.winter AT restena.lu
- Cc: cat-users AT lists.geant.org
- Subject: Re: [[cat-users]] update on consistent Win10 connection failures
- Date: Wed, 7 Nov 2018 08:27:47 -0900
- Authentication-results: prod-mail.geant.net (amavisd-new); dkim=pass (2048-bit key) header.d=alaska-edu.20150623.gappssmtp.com
AddTrust is the root CA but not the issuer of the server cert.
InCommon/Comodo issued the server cert, and that CA cert is signed by AddTrust.
I'll send the cert chain off-list.
David
On Tue, Nov 6, 2018 at 10:24 PM Stefan Winter <stefan.winter AT restena.lu> wrote:
Hello,
> I thought belatedly to Re-read The Fine Manual
> at https://wiki.geant.org/display/H2eduroam/EAP+Server+Certificate+considerations
> which does provide some recommended "non-standard" server certificate
> properties, specifically including SubjectAltName (or "SAN") in addition
> to CN, and certificate extension "TLS Web Server Authentication" -
> neither of which our current server certificate has.
>
> So my working hypothesis is now that we need to get a new server cert
> with those "non-standard" properties added.
Well, I should re-word that page. Most of the items in that list are
indeed fairly standard, only a few stand out (and then only marginally).
I'm however puzzled by what you write. AddTrust is a commercial CA and
the certificates they produce "typically" tick all the boxes. These days
it's hard to come across a CA which doesn't automatically populate the
CN into a subjectAltName:DNS as well.
Would you mind sending me that certificate off-list? Just the public
certificate, no need for the private key :-)
Stefan
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
- [[cat-users]] update on consistent Win10 connection failures, IAM David Bantz, 11/07/2018
- Re: [[cat-users]] update on consistent Win10 connection failures, Stefan Winter, 11/07/2018
- Re: [[cat-users]] update on consistent Win10 connection failures, IAM David Bantz, 11/07/2018
- Re: [[cat-users]] update on consistent Win10 connection failures, Stefan Winter, 11/07/2018
Archive powered by MHonArc 2.6.19.