cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: "[MK] Mikael Klintorp" <address@concealed>, list <address@concealed>
- Subject: Re: [[cat-users]] Certificate revocation problem
- Date: Fri, 16 Nov 2018 12:55:42 +0100
Hello,
> The extension 'CRL Distribution Point' in the server certificate points to
> a location where no DER-encoded CRL can be found. Some Operating Systems
> check certificate validity by consulting the CRL and will fail to validate
> the certificate. Checking server certificate validity against a CRL will
> not be possible.
>
> Strange, because the URL in the CRL Distribution Point section
> (http://www.eg-gym.dk/cert/EspergaerdeGymnasiumAndHF-CA.crl) is up-to-date
> and functional as far as I can test.
That host has an IPv6 address in DNS, but does not answer to any requests.
The TCP timeout is longer than CAT is willing to wait, several minutes.
You may want to fix your webserver.
> wget http://www.eg-gym.dk/cert/EspergaerdeGymnasiumAndHF-CA.crl
--2018-11-16 12:50:58--
http://www.eg-gym.dk/cert/EspergaerdeGymnasiumAndHF-CA.crl
Auflösen des Hostnamens www.eg-gym.dk (www.eg-gym.dk)…
2a02:188:1b01:0:1:0:a0f:4, 5.56.151.66
Verbindungsaufbau zu www.eg-gym.dk
(www.eg-gym.dk)|2a02:188:1b01:0:1:0:a0f:4|:80 … fehlgeschlagen: Die
Wartezeit für die Verbindung ist abgelaufen.
Verbindungsaufbau zu www.eg-gym.dk (www.eg-gym.dk)|5.56.151.66|:80 …
verbunden.
HTTP-Anforderung gesendet, auf Antwort wird gewartet … 200 OK
Länge: 2034 (2,0K) [application/pkix-crl]
Wird in »EspergaerdeGymnasiumAndHF-CA.crl« gespeichert.
EspergaerdeGymnasiumAndHF-CA.crl
100%[===========================================================================================================================================================================================================>]
1,99K --.-KB/s in 0s
2018-11-16 12:53:09 (294 MB/s) - »EspergaerdeGymnasiumAndHF-CA.crl«
gespeichert [2034/2034]
> The Realm Check itself has always failed for our domain, but we have been
> able to logon to other eduroam WiFi's nevertheless. I have no idea when it
> stopped working (my users are not very communicative). At home everything
> works fine for both guests and local users.
>
> Any ideas?
You should start your investigation with the NRO in Denmark. They can
see if roaming requests are actually coming for your realm, and whether
your server responds to such roaming requests.
From the above, a rather wild guess could be that the server has a
hostname with IPv4 and IPv6, DeIC is sending via IPv6, but your server
only actually listens on IPv4?
Greetings,
Stefan Winter
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] Certificate revocation problem,
[MK] Mikael Klintorp, 11/16/2018
- Re: [[cat-users]] Certificate revocation problem, Stefan Winter, 11/16/2018
Archive powered by MHonArc 2.6.19+.
