cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: Per Mejdal Rasmussen <address@concealed>, address@concealed
- Subject: Re: [[cat-users]] "manual" installation instructions
- Date: Fri, 9 Nov 2018 08:11:30 +0100
Hello,
> What we really need to do, is make Android, Linux, MACOS and iOS stop
> supporting GTC. Since Windows does not support GTC. All wireless
> networks that needs to support Windows clients, must support MSCHAPV2.
> Therefor all 802.1x wireless networks that supports username:password
> logins supports MSCHAPv2. GTC is simply not needed.
GTC is not the problem. Once you have an NTHasHash from MS-CHAPv2 you
can recover the plaintext password with relative ease these days. A few
hours worth of cloud computing power get you there. So it's *slightly*
better than PAP or GTC, but don't base any serious security assumption
on it.
The thing we have to achieve is that everybody does configure proper
server settings, and it becomes impossible for an attacker to get any
content from the protected channel inside TLS because his bogus
certificate will be rejected.
Ideally, supplicants would flat out *refuse to connect at all* unless
given sufficient config information by the user or onboarding tool
(saying something equivalent to "I'm sorry, I can't let you do that,
Dave" when the user taps "Connect" without the necessary info).
Greetings,
Stefan Winter
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
Re: [[cat-users]] "manual" installation instructions
, (continued)
-
Re: [[cat-users]] "manual" installation instructions,
address@concealed, 11/05/2018
-
Re: [[cat-users]] "manual" installation instructions,
IAM David Bantz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Stefan Winter, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Alan Buxey, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Tomasz Wolniewicz, 11/06/2018
- Re: [[cat-users]] "manual" installation instructions, IAM David Bantz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Tomasz Wolniewicz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Alan Buxey, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Stefan Winter, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Alan Buxey, 11/06/2018
- Re: [[cat-users]] "manual" installation instructions, Stefan Winter, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
Martin Pauly, 11/07/2018
-
Re: [[cat-users]] "manual" installation instructions,
Per Mejdal Rasmussen, 11/08/2018
- Re: [[cat-users]] "manual" installation instructions, Stefan Winter, 11/09/2018
-
Re: [[cat-users]] "manual" installation instructions,
Per Mejdal Rasmussen, 11/08/2018
-
Re: [[cat-users]] "manual" installation instructions,
IAM David Bantz, 11/06/2018
-
Re: [[cat-users]] "manual" installation instructions,
address@concealed, 11/05/2018
Archive powered by MHonArc 2.6.19+.
