Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] eduroam CAT with Let's Encrypt

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] eduroam CAT with Let's Encrypt


Chronological Thread  
  • From: Mikael Bak <address@concealed>
  • To: address@concealed
  • Subject: Re: [[cat-users]] eduroam CAT with Let's Encrypt
  • Date: Wed, 24 Apr 2019 09:19:20 +0200

Matthew, Tony,
Thank you both for your valuable input!

On 2019. 04. 23. 11:47, Matthew Slowe wrote:
>
>
> Current thinking is that a local, long-lived Root CA (which could be
> dedicated to RADIUS authentication) be used and published via CAT then
> service certificates be issued using that.
>
> There’s a pretty good breakdown of the pros and cons (not specifically
> for LE) here:
>
> https://wiki.geant.org/display/H2eduroam/EAP+Server+Certificate+considerations
>  
>

I'm going to suggest to my collegues that we deploy a dedicated,
long-lived Root CA for eduroam in our organization.

I imagine we're going to give a validity time of 10 years to our Root
CA. But on the other hand, what stops us from give it, let's say 20 or
50 years? Any obvious drawbacks?

TIA,
Mikael Bak



Archive powered by MHonArc 2.6.19+.

Top of Page