cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: Per Mejdal Rasmussen <address@concealed>, "address@concealed" <address@concealed>
- Subject: Re: [[cat-users]] Unique device credentials
- Date: Tue, 2 Apr 2019 09:11:08 +0200
Hello,
> At my university many student devices are not configured to verify the
> radius server certificate, despite we for many years have told the
> students to use the CAT tool.
That's a pity.
> As a consequence we will make system that generates unique credentials
> per device. Where each username/password pair is locked to a specific
> mac address.
Using MAC addresses for access restrictions is a thing of the past. IEEE
and Wi-Fi Alliance push on MAC address randomisation, and if a user has
a sufficiently new device, it may very well be that you'll see a new MAC
address every single time they authenticate. Which makes your
authorisation system defunct.
Also, even if this were not an issue: an attacker with a rogue network
that steals the username and password now also has to take note of the
MAC address of the device, and set that MAC address for his future
exploitation of the credentials. That is hardly a significant hurdle.
> This will make it impossible to reuse stolen eduroam credentials for
> other systems, and make it very hard to use stolen credentials on other
> devices.
>
> I was wondering if anyone else has made a similar system, or know of a
> system you can buy for that purpose?
>
> The reason we don't just use device certificates, is that it is not as
> widely supported as username/password in devices.
Quite frankly: the solution is indeed client certificates. The private
keys can't be stolen by a MitM, they are independent from MAC, and are
"reasonably" device-bound. I.e. a savvy user might know how to extract
them, and install in a different device; but most don't. A user that
savvy can however probably also manually set a MAC address.
For small user populations, we offer the product "eduroam Managed IdP"
which works with per-device client credentials. It is not intended to be
used for large user bases such as "thousands of students" though. If you
want to try this out, please get in touch with your eduroam National
Roaming Operator in Denmark (Danish e-Infrastructure Cooperation - DeiC).
Greetings,
Stefan Winter
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
Re: [[cat-users]] Unique device credentials,
Workman, John R, 04/01/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/02/2019
- <Possible follow-up(s)>
-
Re: [[cat-users]] Unique device credentials,
Stefan Winter, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Per Mejdal Rasmussen, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Stefan Winter, 04/02/2019
-
[[cat-users]] Eduroam vs Security,
Andre Forigato, 04/02/2019
- Re: [[cat-users]] Eduroam vs Security, Stefan Winter, 04/02/2019
- Re: [[cat-users]] Eduroam vs Security, Martin Pauly, 04/03/2019
-
Re: [[cat-users]] Unique device credentials,
Daniele Albrizio, 04/03/2019
- Re: [[cat-users]] Unique device credentials, Stefan Winter, 04/09/2019
- Re: [[cat-users]] Unique device credentials, Per Mejdal Rasmussen, 04/12/2019
-
[[cat-users]] Eduroam vs Security,
Andre Forigato, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Stefan Winter, 04/02/2019
-
Re: [[cat-users]] Unique device credentials,
Per Mejdal Rasmussen, 04/02/2019
Archive powered by MHonArc 2.6.19+.
