cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: IAM David Bantz <dabantz AT alaska.edu>
- To: Alan Buxey <alan.buxey AT gmail.com>
- Cc: Michael.Davies AT gowercollegeswansea.ac.uk, cat-users AT lists.geant.org
- Subject: Re: [[cat-users]] eduroam Issue
- Date: Tue, 11 Dec 2018 09:54:39 -0900
- Authentication-results: prod-mail.geant.net (amavisd-new); dkim=pass (2048-bit key) header.d=alaska-edu.20150623.gappssmtp.com
Our pre-deployment testing of expired password behavior of supplicants on most current release of iOS, Android, macOS, and Windows with CAT-installed profiles determined that it is not necessary to re-install the profile for a changed password in the authentication source. Of course the supplicants configured with invalid password will fail to connect; but if the user manually initiates connection to eduroam SSID, they are prompted for the correct password; once the correct new password is entered, automatic connection to eduroam is restored. YMMV
David Bantz
U Alaska
On Tue, Dec 11, 2018 at 6:47 AM Alan Buxey <alan.buxey AT gmail.com> wrote:
hi,yes, unfortunately most mobile platforms have issues with stored profile passwords if the user has changed them - repeated failures to auth - usually remeied easily by just rejoining thenetwork after forgetting it (at that point, if not using a deployment tool such as eduroamCAT, the new connection will be without checking the RADIUS cert correctly).so, use EAP-TLS certs instead (self-enroll using their current user/password to get a cert that is only for wireless) - Aruba clearpass etc etcor maybe look at your password policy - why changing them every 3 months? the current security best practices is to ensure the password is strong and ONLY change it ifthere is a reason to believe that its been compromised, use multi factor auth where possible etc.alanTo unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users
- [[cat-users]] eduroam Issue, Michael Davies (Infrastructure Mgr), 12/11/2018
- Re: [[cat-users]] eduroam Issue, Stefan Winter, 12/11/2018
- Re: [[cat-users]] eduroam Issue, Alan Buxey, 12/11/2018
- Re: [[cat-users]] eduroam Issue, IAM David Bantz, 12/11/2018
- RE: [[cat-users]] eduroam Issue, Michael Davies (Infrastructure Mgr), 12/12/2018
- Re: [[cat-users]] eduroam Issue, Tomasz Wolniewicz, 12/13/2018
- Re: [[cat-users]] eduroam Issue, IAM David Bantz, 12/13/2018
- Re: [[cat-users]] eduroam Issue, Tomasz Wolniewicz, 12/13/2018
- RE: [[cat-users]] eduroam Issue, Michael Davies (Infrastructure Mgr), 12/12/2018
- Re: [[cat-users]] eduroam Issue, IAM David Bantz, 12/11/2018
Archive powered by MHonArc 2.6.19.