cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Tomasz Wolniewicz <address@concealed>
- To: address@concealed
- Subject: Re: [[cat-users]] cat.eduroam.org TLS iOS
- Date: Thu, 31 Jan 2019 08:52:37 +0100
Hi,
I have just run a test.
1. installed the p12 user certificate from our CA
2. installed the TLS mobileconfig profile
3. connected to eduroam and was prompted to provide identity. I selected
the profile that was created when the p12 was being installed. Finally I
gad to change from automatic method to EAP-TLS and this made the
"connect" active. After that my phone connected just fine, extracting
the username from the CN of the personal certificate.
Seems that iOS can actually do it - not the easiest of methods, but still.
Tomasz
W dniu 31.01.2019 o 08:30, Stefan Winter pisze:
> Hello,
>
>> we created a cat profile containing only EAP-TLS as an authentication
>> method.
>>
>> The “installer” (a .mobileconfig Apple profile) seems to be unavailable
>> to download for iOS devices.
>>
>> That’ strange because the same profile, available to download from cat,
>> for Apple OSX, if installed on iOS is 100% compatible with iOS and
>> useful to autoconfigure iOS iPads or iPhone.
>>
>> Can you make it available also for iOS users or I am missing something?
> This was done intentionally at the time.
>
> iOS can download a TLS profile and install it just fine.
>
> However, the profiles naturally do not contain an actual client certificate.
>
> Earlier versions of iOS we tested were unable to associate a
> already-installed TLS client certificate (i.e. imported as a stand-alone
> .p12 file) with the newly installed Wi-Fi profile. This rendered the
> entire installation process pointless.
>
> What you write above seems to imply that things have changed? Did you
> actually *use* the Wi-Fi profile with a pre-installed client certificate
> and did that work? How does the initial connection dialog look like, if
> any? Are you asked about the client certificate, or will it just pick
> the (one and only) client cert it finds in the device?
>
> Greetings,
>
> Stefan Winter
>
--
Tomasz Wolniewicz
address@concealed http://www.home.umk.pl/~twoln
Uczelniane Centrum Informatyczne Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University,
pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750 tel kom.: +48-693-032-576
Attachment:
smime.p7s
Description: Kryptograficzna sygnatura S/MIME
-
[[cat-users]] cat.eduroam.org TLS iOS,
Pierluigi Checchi, 01/30/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Stefan Winter, 01/31/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Tomasz Wolniewicz, 01/31/2019
- Re: [[cat-users]] cat.eduroam.org TLS iOS, Stefan Winter, 01/31/2019
- RE: [[cat-users]] cat.eduroam.org TLS iOS, Pierluigi Checchi, 01/31/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Tomasz Wolniewicz, 01/31/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Stefan Winter, 01/31/2019
Archive powered by MHonArc 2.6.19+.
