cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
Re: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled
Chronological Thread
- From: Tomasz Wolniewicz <twoln AT umk.pl>
- To: "Johnson, Christopher" <cbjohns AT ilstu.edu>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Subject: Re: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled
- Date: Fri, 11 Jan 2019 15:49:03 +0100
- Autocrypt: addr=twoln AT umk.pl; keydata= mQENBEvhYBEBCADIlSk8hnUtSfZ1hLbuqiUxTiBtm65lM6OlxjYnWEsH/boOsVS/WdFZebwK 53eg280UcX9VDjFjy5rimsknCvxabnxk13AF//t9mN9tq5MmIkIcRIpLrtqc8Q0s0E84cNzB bDMtRzAd7JUTmKyAnkKE9i2R9FJKzeR9TTeKtBdgXHtUKPHPGOdxUUv8UWKxsj9AYi2CgN98 jiWLx6lTIpaWegWxIyih7WUKSf43Bpi6wFxhfOxteLyQUpIlGg4CasTVGpFsha8KzlupXOLG Tl3hXtQFWvE0tl1GidvTyuQlOzsZ1vjTNEzI25VTkOIgP4IYcWSkP74p/a239ZcTOHhZABEB AAG0IFRvbWFzeiBXb2xuaWV3aWN6IDx0d29sbkB1bWsucGw+iQE4BBMBAgAiBQJL4WARAhsD BgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRA8PEwxkb+lPgkeB/9NAGlmopLel6EEDFz2 ra3KLBx8kXT3G1K/YYyrjDwNjCkAmm0evzQx8g9vPX2OzvE6Ai2Xi9hPd2K/ShPFPcgJzzjr h9H1XYfBb2N/tRwN9tb4XO5i9Tsa4jP+SG8h2yQY57QOeFy16joDmIZiZrAEIGpqqSV24PrX FSo2d1E4dMswqDXlEYk9hwbdW9H4zOQrnDZeRlRx/RW/cmWTd8r5C12dKhlT/D/fBkL3eYT7 rnjHtS+ArnMUsxu2Z/q6bmxqRyv4Vn4pR0n699iLa0ol2hWeQJFaZyTA7JksW8zWu/Zasd9K Dw3jM59vs/SXVdG8pMexAzH5jmEEAgwYwUbVuQENBEvhYBEBCACgAz/z7VTnCsPSBUrjCLyS j+eRtr2tQzSU48Qa5hOcIxAKQJQNgOOqs0Mq9fT9lV+OttaYyKtijt1+G2dVMETVFkdZmM0c g8pVJp398993v89U/iwjfvNoqCM/9z312Poha/oL/EOk+gWYxZbyQ18SY69va2WHr6Pl3bzR 6BQpb86W85MreQ2lxd76b6BgjOXA/b39YyU/fMeFQd+wDpT3K1fUr89dYRnyzQIxTBSPOMLQ ShHKc/S8dStbNlLNcnaiyBOsH4A7b6IizQGqyVHBeL7u05X0/ZVdEIgsO3NmQouqY0/WjBdV qg4EsI1VvvgwXKWafP1MryLy4ZcnNjQZABEBAAGJAR8EGAECAAkFAkvhYBECGwwACgkQPDxM MZG/pT6lUQf8DC3i15okq3VycbpTYuH6f1lQkqanMS0z4z8F6xtCeXq0DBFk0ZzAU/mCwc3V PdUVGtRKGjouSAB1HDeTvAth1vY0oOJG3kXBwkcui3QxM3sxksNCRLLwcZVnsK9rt6UVp5aG qBwKf44BSApGyHNuKDhCfMCQHueqlfhJYfXocw6KDObvTkwygHLmw93ohV66v26yNvGo6+q2 qTDykGyuicACPDTyJTWFh2IwwZFAdzcc7St8aKkXFk0zWvoriWHeTLUnuFw7HN640IJkG74a 4NGco2yPc7Cz6q59rgE9xydOOXRdmnfiuJu0kQvQocD1rVLjW3qXdnxPd2/FhO4vWg==
- Openpgp: preference=signencrypt
Hi Christopher, this indeed looks like a lowest impact approach even if, in the end it will probably prove unnecessary, as the current user should probably be used every time. Still unexpected things pop up, and I found out that our method of populating user credentials does not seem to work when the wireless profile is not global. As a result we could end up in a situation whee we ask the user for credentials, install the non-global profile and then the user would get prompted for credentials. This is not very clean, so we need to take a closer look, but we are working on it. Tomasz
W dniu 11.01.2019 o 02:04, Johnson,
Christopher pisze:
Hi Tomasz,
I forgot to mention in my previous response - in regards to "logic being built in" was also intended more of a suggestion/request for a "if else" type of situation - where the educatCAT could check if "createallusergroup" is enabled. - If enabled, run the netsh command as normal - If the check fails, then attempt the "user=current" switch.
Thanks again! Looking forward to seeing how eduroam goes. We went live yesterday with the initial broadcasting. 😊
Christopher Johnson From:
Johnson, Christopher
Sent: Thursday, January 10, 2019 2:55:54 PM To: Tomasz Wolniewicz; cat-users AT lists.geant.org Subject: RE: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled Hi Tomasz,
Thanks for the response and feedback. You’re correct at is indeed a pretty limited use-case – as you mentioned most managed machines are auto-provisioned via group-policy and such through other means. Sometimes we see this type of behavior when a student brings their work laptop from an internship or business school that’s heavily locked down or a teacher taking classes may bring their work laptop as well – since that createalluserprofile limitation can be a global setting.
What’s funny is this is also a problem with the legacy CloudPath XpressConnect Wizard as well that I spent time troubleshooting a few months ago. But only today did I find a potential enhancement via the “user=current switch”. That’s part of how I caught on to it so quickly as I spent a good amount of time troubleshooting the other onboarding product.
I definitely understand a lot of testing should be done before making this change if consideration is made for it.
Thanks for your time and consideration!
Christopher Johnson Wireless Network Engineer AT Infrastructure Operations & Networking (ION) Illinois State University (309) 438-8444 Stay connected with ISU IT news and tips with @ISU IT Help on Facebook and TwitterFrom: Tomasz Wolniewicz
<twoln AT umk.pl>
Hi, What you suggest makes a lot of sense. eduroam credentials are personal therefore should be restricted to the current user. Besides the installed root CA will be limited to the the current user anyway, so the profile should not work for others. It would seem that adding user=current to netsh should be safe for everyone, but surely we should run quite a bit of testing before making this change. On the other hand, we imagined that in a managed Windows environment the network provisioning would be done centrally anyway, this is probably why we never got this request before. Tomasz Wolniewicz W dniu 10.01.2019 o 20:10, Johnson, Christopher pisze:
-- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uczelniane Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750 fax: +48-56-622-1850 tel kom.: +48-693-032-576To unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users -- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uczelniane Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750 tel kom.: +48-693-032-576 |
Attachment:
smime.p7s
Description: Kryptograficzna sygnatura S/MIME
- [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Johnson, Christopher, 01/10/2019
- Re: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Tomasz Wolniewicz, 01/10/2019
- RE: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Johnson, Christopher, 01/10/2019
- Re: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Johnson, Christopher, 01/11/2019
- Re: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Tomasz Wolniewicz, 01/11/2019
- Re: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Johnson, Christopher, 01/11/2019
- RE: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Johnson, Christopher, 01/10/2019
- Re: [[cat-users]] Windows 10 - eduroamCAT utility fails due to "createalluserprofile" flag set to disabled, Tomasz Wolniewicz, 01/10/2019
Archive powered by MHonArc 2.6.19.