Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] update on consistent Win10 connection failures

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] update on consistent Win10 connection failures


Chronological Thread 
  • From: IAM David Bantz <db AT alaska.edu>
  • To: stefan.winter AT restena.lu
  • Cc: cat-users AT lists.geant.org
  • Subject: Re: [[cat-users]] update on consistent Win10 connection failures
  • Date: Wed, 7 Nov 2018 08:27:47 -0900
  • Authentication-results: prod-mail.geant.net (amavisd-new); dkim=pass (2048-bit key) header.d=alaska-edu.20150623.gappssmtp.com

AddTrust is the root CA but not the issuer of the server cert. 
InCommon/Comodo issued the server cert, and that CA cert is signed by AddTrust.
I'll send the cert chain off-list.

David

On Tue, Nov 6, 2018 at 10:24 PM Stefan Winter <stefan.winter AT restena.lu> wrote:
Hello,

> I thought belatedly to Re-read The Fine Manual
> at https://wiki.geant.org/display/H2eduroam/EAP+Server+Certificate+considerations
> which does provide some recommended "non-standard" server certificate
> properties, specifically including SubjectAltName (or "SAN") in addition
> to CN, and certificate extension "TLS Web Server Authentication" -
> neither of which our current server certificate has. 
>
> So my working hypothesis is now that we need to get a new server cert
> with those "non-standard" properties added. 

Well, I should re-word that page. Most of the items in that list are
indeed fairly standard, only a few stand out (and then only marginally).

I'm however puzzled by what you write. AddTrust is a commercial CA and
the certificates they produce "typically" tick all the boxes. These days
it's hard to come across a CA which doesn't automatically populate the
CN into a subjectAltName:DNS as well.

Would you mind sending me that certificate off-list? Just the public
certificate, no need for the private key :-)

Stefan

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66



Archive powered by MHonArc 2.6.19.

Top of Page