Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Instalador Acesso wireless eduroam IPSantarem

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Instalador Acesso wireless eduroam IPSantarem


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Pedro Tiago Lima de Carvalho <address@concealed>, "address@concealed" <address@concealed>
  • Cc: Alexandre Manuel Santareno Pimenta <address@concealed>
  • Subject: Re: [[cat-users]] Instalador Acesso wireless eduroam IPSantarem
  • Date: Wed, 23 Jan 2019 16:59:38 +0100

Hello,


> Quando usamos o instalador, este não funciona, pede constantemente o user e
> password e não fica instalado.
> Neste momento estamos a fazer a configuração manualmente, vou enviar os
> passos que utilizamos no documento anexo.


Those configuration instructions tell users NOT to validate the server
certificate.


This subjects users to rogue server attacks; their devices will happily
send their usernames and passwords to arbitrary servers.


Telling users to configure like that is a violation of the European
eduroam Service Definition.


Naturally, CAT installers do not support this mode of operation. In CAT,
you *must* specify the root CA that issued your server certificate, and
you *must* specify the server name in that certificate.


If you supply that information correctly, then the installers work just
fine.


If you find them not working, please let us know how you configured CAT
- the CA(s) you uploaded, the server names you specified, and the realm
under which your institution is participating in eduroam. We can then
further help you find out what's wrong.


Greetings,


Stefan Winter

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page