cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: "Downton, Sam" <address@concealed>, "address@concealed" <address@concealed>
- Subject: Re: [[cat-users]] TLS Failures from Android
- Date: Mon, 14 Jan 2019 14:49:10 +0100
Hi,
> Our Radius Server does send the whole chain during the EAP exchange, and I
> can use the root cert installed by CAT to verify the servers identity when
> manually entering the configuration, the problem seems to be specific to
> the combination of settings applied by CAT.
Okay... the thing is, we don't do anything special. It's an API call to
Android's built-in WifiEnterprise API, everything from then on is just
normal Android supplicant behaviour.
> As mentioned by Alan, our firewall will only allow a direct RADIUS
> connection from the UK proxies. I have rasied a call with JISC asking why
> we are seeing errors in their portal while running the connectivity tests
> from the CAT website.
I take that for granted. It is not even possible at all to contact you
directly because I do not have a shared secret on your server, and you
do not have a RADIUS/TLS certificate for direct peering.
My test /originated/ from our NRO server, but was injected into normal
eduroam routing. So it first went to the European top-level servers, who
proxied to the UK ones, who sent it onwards to you. This traverses the
firewalls just fine.
And then, there was no reply.
Good that you mention that the UK support servers also see errors. This
means I'm not dreaming anything up and there are others who see that
something in your realm's request routing is wrong, too. (The CAT tests
inject their tests on the European top-level servers and thus take by
and large the same way to you as my LU tests do)
The UK servers are of course closer to you than any test I can run. I
suggest once you've cleared the error cause on the national level, we
can regroup and try testing from CAT again.
> Thanks for the info about ChromeOS. This will be something to consider when
> we next renew our certificate.
You're welcome.
Stefan
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] TLS Failures from Android,
Downton, Sam, 01/11/2019
-
Re: [[cat-users]] TLS Failures from Android,
Stefan Winter, 01/14/2019
-
RE: [[cat-users]] TLS Failures from Android,
Downton, Sam, 01/14/2019
-
Re: [[cat-users]] TLS Failures from Android,
Stefan Winter, 01/14/2019
-
Re: [[cat-users]] TLS Failures from Android,
Stefan Winter, 01/14/2019
- Re: [[cat-users]] TLS Failures from Android, Alan Buxey, 01/14/2019
-
RE: [[cat-users]] TLS Failures from Android,
Downton, Sam, 01/14/2019
- Re: [[cat-users]] TLS Failures from Android, Stefan Winter, 01/14/2019
-
Re: [[cat-users]] TLS Failures from Android,
Stefan Winter, 01/14/2019
-
Re: [[cat-users]] TLS Failures from Android,
Stefan Winter, 01/14/2019
-
RE: [[cat-users]] TLS Failures from Android,
Downton, Sam, 01/14/2019
-
Re: [[cat-users]] TLS Failures from Android,
Stefan Winter, 01/14/2019
Archive powered by MHonArc 2.6.19+.
