Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] TLS Failures from Android

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] TLS Failures from Android


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: "Downton, Sam" <address@concealed>, "address@concealed" <address@concealed>
  • Subject: Re: [[cat-users]] TLS Failures from Android
  • Date: Mon, 14 Jan 2019 09:03:58 +0100

Hello,

> The opposite is true unfortunately! The clients we are experiencing the
> issue on are Google Pixel 2 phones running Android 9. They have no issue
> connecting to our eduroam implementation when configured manually, so it
> would appear to be a configuration issue rather than a lack of
> compatibility with the infrastructure.

That's quite interesting. Can you confirm that version /before/ 9 work
with the CAT profiles?

When you write "manual configuration" then that probably means just
username and password, without cert validation?

If it fails with cert validation, but not without, then maybe it's a
property of the cert that upsets the newest Android.

Unfortunately, your IdP server seems to run on a Windows NPS or other
RADIUS server configuration that rejects incoming requests if the outer
ID does not match a known user - so I can't actually get to see the
server cert for manual inspection.

You could either edit your profile properties to add the "Use special
Outer Identity for realm checks" and fill in a valid username - that way
the CAT tests could get through to the actual EAP exchange; or just send
me the server cert off-list so I can take a look.

Greetings,

Stefan Winter

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page