Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Problem with Eduroam CAT at Weizmann Institute of Science

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Problem with Eduroam CAT at Weizmann Institute of Science


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Naor Elkayam <address@concealed>, address@concealed
  • Cc: Oron Yaniv <address@concealed>
  • Subject: Re: [[cat-users]] Problem with Eduroam CAT at Weizmann Institute of Science
  • Date: Mon, 18 Feb 2019 08:08:21 +0100

Hello,

> We are having problems with users trying to connect to Eduroam after
> installing the profile via CAT.
>
> We can see that altho the user enter his credentials in the installer,
> out RADIUS logs shows that all users are trying to connect with the same
> username: “eduroam.weizmann.ac.il” and
> obviously fails to authenticate.

Looking at your CAT profile settings, I see that you have enabled the
"Use anonymous outer identity" setting, have set the local part to
"eduroam" and the realm is weizmann.ac.il

This means all users will authenticate with the same anonymous outer
identity "address@concealed". There is nothing wrong with everyone
coming in the same outer identity. It's a privacy-enhancing feature and
as an administrator you can either turn it on or off.

Of course your RADIUS server must be capable of handling that, i.e. able
to extract the actual usernames from within the protected TLS tunnel in
PEAP's phase 2. Obviously, you should only configure anonymous outer
identities in CAT if your RADIUS server is configured to handle them.

The only thing that would worry me here is that you write the outer
username starts with "eduroam." instead of "eduroam@". Was that a typo,
or is that part of your statement the actual problem you have?

> Please fix it as soon as you can because we have dozens of users abroad
> and the manual standard method is impractical to do by phone or emails.

On the flip side, we have thousands of IdPs using the anonymous outer ID
feature and we didn't get any problem reports so far. So I'd be
surprised if this feature were deterministically broken. If you do see
wrong username construction, it might be helpful to tell us which
operating system's installers exhibit these failures.

Greetings,

Stefan Winter

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page