Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] ChromeOS .onc file

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] ChromeOS .onc file


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Robert Grätz <address@concealed>, address@concealed
  • Subject: Re: [[cat-users]] ChromeOS .onc file
  • Date: Fri, 10 May 2019 08:29:12 +0200

Hi,

> I have 2 questions. How could I define a second wifi network like
> eduroam and eduroam2 in the .onc file? Is this the correct consideration?
>
> "NetworkConfigurations": [
>
> {"Name": "eduroam", ... },
> {"Name": "eduroam2", ... }]

You are on a wrong track there. Rather than editing the generated .onc
file, simply add a second SSID in the CAT configuration. It will then
generate an .onc file which has both SSIDs inside by itself.

> And why doesn't work eduroam if I define an user certificate like the
> T-Telesec? The manual proposes that I should choose "None installed".
> I don't think this is a good idea, isn't it?

Again, you are looking at the wrong place. That manual installs a
CAT-generated .onc file which has a CA certificate inside. CAT doesn't
even let you generate config files without a root CA.

The screenshot shows an item labelled *user* certificate - None
installed. That's correct because TTLS (or PEAP for that matter) use
passwords to identify users, not user certificates.

That is, on paper there is a possibility to use passwords *and* client
certificates together with PEAP and TTLS. But no eduroam IdP I've
encountered so far does that. If you are the first, please let me know.

Greetings,

Stefan Winter

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0xC0DE6A358A39DC66.asc
Description: application/pgp-keys




Archive powered by MHonArc 2.6.19+.

Top of Page