Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Unique device credentials

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Unique device credentials


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Per Mejdal Rasmussen <address@concealed>, "address@concealed" <address@concealed>
  • Subject: Re: [[cat-users]] Unique device credentials
  • Date: Tue, 2 Apr 2019 09:11:08 +0200

Hello,

> At my university many student devices are not configured to verify the
> radius server certificate, despite we for many years have told the
> students to use the CAT tool.

That's a pity.

> As a consequence we will make system that generates unique credentials
> per device. Where each username/password pair is locked to a specific
> mac address.

Using MAC addresses for access restrictions is a thing of the past. IEEE
and Wi-Fi Alliance push on MAC address randomisation, and if a user has
a sufficiently new device, it may very well be that you'll see a new MAC
address every single time they authenticate. Which makes your
authorisation system defunct.

Also, even if this were not an issue: an attacker with a rogue network
that steals the username and password now also has to take note of the
MAC address of the device, and set that MAC address for his future
exploitation of the credentials. That is hardly a significant hurdle.

> This will make it impossible to reuse stolen eduroam credentials for
> other systems, and make it very hard to use stolen credentials on other
> devices.
>
> I was wondering if anyone else has made a similar system, or know of a
> system you can buy for that purpose?
>
> The reason we don't just use device certificates, is that it is not as
> widely supported as username/password in devices.

Quite frankly: the solution is indeed client certificates. The private
keys can't be stolen by a MitM, they are independent from MAC, and are
"reasonably" device-bound. I.e. a savvy user might know how to extract
them, and install in a different device; but most don't. A user that
savvy can however probably also manually set a MAC address.

For small user populations, we offer the product "eduroam Managed IdP"
which works with per-device client credentials. It is not intended to be
used for large user bases such as "thousands of students" though. If you
want to try this out, please get in touch with your eduroam National
Roaming Operator in Denmark (Danish e-Infrastructure Cooperation - DeiC).

Greetings,

Stefan Winter

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page