cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Tomasz Wolniewicz <twoln AT umk.pl>
- To: cat-users AT lists.geant.org
- Subject: Re: [[cat-users]] EAP-TLS issues
- Date: Wed, 24 Apr 2019 10:33:11 +0200
- Autocrypt: addr=twoln AT umk.pl; keydata= mQENBEvhYBEBCADIlSk8hnUtSfZ1hLbuqiUxTiBtm65lM6OlxjYnWEsH/boOsVS/WdFZebwK 53eg280UcX9VDjFjy5rimsknCvxabnxk13AF//t9mN9tq5MmIkIcRIpLrtqc8Q0s0E84cNzB bDMtRzAd7JUTmKyAnkKE9i2R9FJKzeR9TTeKtBdgXHtUKPHPGOdxUUv8UWKxsj9AYi2CgN98 jiWLx6lTIpaWegWxIyih7WUKSf43Bpi6wFxhfOxteLyQUpIlGg4CasTVGpFsha8KzlupXOLG Tl3hXtQFWvE0tl1GidvTyuQlOzsZ1vjTNEzI25VTkOIgP4IYcWSkP74p/a239ZcTOHhZABEB AAG0IFRvbWFzeiBXb2xuaWV3aWN6IDx0d29sbkB1bWsucGw+iQE4BBMBAgAiBQJL4WARAhsD BgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRA8PEwxkb+lPgkeB/9NAGlmopLel6EEDFz2 ra3KLBx8kXT3G1K/YYyrjDwNjCkAmm0evzQx8g9vPX2OzvE6Ai2Xi9hPd2K/ShPFPcgJzzjr h9H1XYfBb2N/tRwN9tb4XO5i9Tsa4jP+SG8h2yQY57QOeFy16joDmIZiZrAEIGpqqSV24PrX FSo2d1E4dMswqDXlEYk9hwbdW9H4zOQrnDZeRlRx/RW/cmWTd8r5C12dKhlT/D/fBkL3eYT7 rnjHtS+ArnMUsxu2Z/q6bmxqRyv4Vn4pR0n699iLa0ol2hWeQJFaZyTA7JksW8zWu/Zasd9K Dw3jM59vs/SXVdG8pMexAzH5jmEEAgwYwUbVuQENBEvhYBEBCACgAz/z7VTnCsPSBUrjCLyS j+eRtr2tQzSU48Qa5hOcIxAKQJQNgOOqs0Mq9fT9lV+OttaYyKtijt1+G2dVMETVFkdZmM0c g8pVJp398993v89U/iwjfvNoqCM/9z312Poha/oL/EOk+gWYxZbyQ18SY69va2WHr6Pl3bzR 6BQpb86W85MreQ2lxd76b6BgjOXA/b39YyU/fMeFQd+wDpT3K1fUr89dYRnyzQIxTBSPOMLQ ShHKc/S8dStbNlLNcnaiyBOsH4A7b6IizQGqyVHBeL7u05X0/ZVdEIgsO3NmQouqY0/WjBdV qg4EsI1VvvgwXKWafP1MryLy4ZcnNjQZABEBAAGJAR8EGAECAAkFAkvhYBECGwwACgkQPDxM MZG/pT6lUQf8DC3i15okq3VycbpTYuH6f1lQkqanMS0z4z8F6xtCeXq0DBFk0ZzAU/mCwc3V PdUVGtRKGjouSAB1HDeTvAth1vY0oOJG3kXBwkcui3QxM3sxksNCRLLwcZVnsK9rt6UVp5aG qBwKf44BSApGyHNuKDhCfMCQHueqlfhJYfXocw6KDObvTkwygHLmw93ohV66v26yNvGo6+q2 qTDykGyuicACPDTyJTWFh2IwwZFAdzcc7St8aKkXFk0zWvoriWHeTLUnuFw7HN640IJkG74a 4NGco2yPc7Cz6q59rgE9xydOOXRdmnfiuJu0kQvQocD1rVLjW3qXdnxPd2/FhO4vWg==
- Openpgp: preference=signencrypt
Hi,
W dniu 24.04.2019 o 10:13, NAKAMURA Motonori pisze:
> Hello,
>
> I've just tried to configure my devices with an EAP-TLS profile/CAT,
> and there are some issues.
>
> 0. I added a EAP-TLS item to an existing profile only with EAP-PEAP,
> After that, I want to delete the added EAP-TLS item from the profile
> to separate int two profiles -- EAP-PEAP profile and EAP-TLS profile.
> But I cannot remove the EAP-TLS item from the existing profile. After
> clicking "save data", EAP-TLS appears again...
You mean, you drag TLS to the lower square and save? I have just tested
this on the production CAT and everything went smoothly as expected.
>
> 2. with Windows10 Pro (1809), it works. But the installer requires
> .p12 file on installation. I'd like to use an already installed client
> certificate... (It seems Windows10 automatically finds ID from CN in
> the certificate)
I think that the user experience is better in you require the p12 file.
suppose you want to renew the certificate with the same CN. If the user
just installs the cert first, they will get to choose from two seemingly
identical. There may also be other certs in the system, making user to
select the appropriate one can be hard. I used to have a special setting
for my university, where the system would look for certs with a CN
matching a pattern and automatically using an installed one if it was
found, but again this causes problems with renewing the cert. The
current process actually pins the cert supplied within the p12 file
which is a very good thing.
If you really feel strongly about changing the current behaviour, then
we could discuss the details.
>
> 3. with Android 8.0.0, it does not work. No inquiry to specify a
> client certificate, even if a client certificate has been already
> installed.
This I will leave to Gareth.
Tomasz
>
> Best regards,
> ---
> Motonori NAKAMURA <motonori AT nii.ac.jp>
> National Institute of Informatics/Kyoto University, JAPAN
>
>
> To unsubscribe, send this message:
> mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
> Or use the following link:
> https://lists.geant.org/sympa/sigrequest/cat-users
--
Tomasz Wolniewicz
twoln AT umk.pl http://www.home.umk.pl/~twoln
Uczelniane Centrum Informatyczne Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University,
pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750 tel kom.: +48-693-032-576
Attachment:
smime.p7s
Description: Kryptograficzna sygnatura S/MIME
- [[cat-users]] EAP-TLS issues, NAKAMURA Motonori, 04/24/2019
- Re: [[cat-users]] EAP-TLS issues, Tomasz Wolniewicz, 04/24/2019
- Re: [[cat-users]] EAP-TLS issues, NAKAMURA Motonori, 04/24/2019
- Re: [[cat-users]] EAP-TLS issues, Tomasz Wolniewicz, 04/24/2019
- Re: [[cat-users]] EAP-TLS issues, NAKAMURA Motonori, 04/24/2019
- Re: [[cat-users]] EAP-TLS issues, Tomasz Wolniewicz, 04/24/2019
- Re: [[cat-users]] EAP-TLS issues, NAKAMURA Motonori, 04/24/2019
- Re: [[cat-users]] EAP-TLS issues, Tomasz Wolniewicz, 04/24/2019
Archive powered by MHonArc 2.6.19.