cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: Tomasz Wolniewicz <address@concealed>, address@concealed
- Subject: Re: [[cat-users]] cat.eduroam.org TLS iOS
- Date: Thu, 31 Jan 2019 09:06:15 +0100
Hi,
> I have just run a test.
>
> 1. installed the p12 user certificate from our CA
>
> 2. installed the TLS mobileconfig profile
>
> 3. connected to eduroam and was prompted to provide identity. I selected
> the profile that was created when the p12 was being installed. Finally I
> gad to change from automatic method to EAP-TLS and this made the
> "connect" active. After that my phone connected just fine, extracting
> the username from the CN of the personal certificate.
>
> Seems that iOS can actually do it - not the easiest of methods, but still.
That's great news!
Question is, from which version onwards can we enable the TLS profiles then.
If you'd happen to know if this already started working a few releases
back, we'd have a good indicator (I only have iOS 12 here).
If not, we could always split out the "iOS 7+" button into a "iOS 7-11"
and "iOS 12+" where only the 12+ has EAP-TLS marked as usable.
Greetings,
Stefan Winter
>
> Tomasz
>
>
> W dniu 31.01.2019 o 08:30, Stefan Winter pisze:
>> Hello,
>>
>>> we created a cat profile containing only EAP-TLS as an authentication
>>> method.
>>>
>>> The “installer” (a .mobileconfig Apple profile) seems to be unavailable
>>> to download for iOS devices.
>>>
>>> That’ strange because the same profile, available to download from cat,
>>> for Apple OSX, if installed on iOS is 100% compatible with iOS and
>>> useful to autoconfigure iOS iPads or iPhone.
>>>
>>> Can you make it available also for iOS users or I am missing something?
>> This was done intentionally at the time.
>>
>> iOS can download a TLS profile and install it just fine.
>>
>> However, the profiles naturally do not contain an actual client
>> certificate.
>>
>> Earlier versions of iOS we tested were unable to associate a
>> already-installed TLS client certificate (i.e. imported as a stand-alone
>> .p12 file) with the newly installed Wi-Fi profile. This rendered the
>> entire installation process pointless.
>>
>> What you write above seems to imply that things have changed? Did you
>> actually *use* the Wi-Fi profile with a pre-installed client certificate
>> and did that work? How does the initial connection dialog look like, if
>> any? Are you asked about the client certificate, or will it just pick
>> the (one and only) client cert it finds in the device?
>>
>> Greetings,
>>
>> Stefan Winter
>>
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] cat.eduroam.org TLS iOS,
Pierluigi Checchi, 01/30/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Stefan Winter, 01/31/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Tomasz Wolniewicz, 01/31/2019
- Re: [[cat-users]] cat.eduroam.org TLS iOS, Stefan Winter, 01/31/2019
- RE: [[cat-users]] cat.eduroam.org TLS iOS, Pierluigi Checchi, 01/31/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Tomasz Wolniewicz, 01/31/2019
-
Re: [[cat-users]] cat.eduroam.org TLS iOS,
Stefan Winter, 01/31/2019
Archive powered by MHonArc 2.6.19+.
