cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: Martin Pauly <address@concealed>, address@concealed, José Manuel Agudo Cuesta <address@concealed>
- Subject: Re: [[cat-users]] Feature Request: Have CAT apps look for profile updates?
- Date: Thu, 11 Jul 2019 08:51:18 +0200
Hello,
we've discussed the merits and drawbacks of such an auto-update feature
a number of times, without a clear winner.
The more I think of it (and witnessing the backscatter of the
disgruntlements of the currently ongoing Germany CA change) I think this
problem is bigger than CAT; solving it in an app would be all nice for
those who use the system but it leaves everyone else still cold in the
rain (some study gauged the amount of users subjected to CAT to be
around 50% of the total eduroamer population - so there's another 50%;
and also every other Wi-Fi Enterprise deployer on the planet).
I think it would be possible to do a CA rollover "cleanly" via the
protocols we have; all that would be needed is a convention that is to
be adhered to by supplicants.
A mechanism that could work would be:
If the client is configured with the current root CA A, and an EAP
authentication happens which is authenticated by the correct expected
server certificate S, with full chain in place:
check if there are any additional *root* CAs A', A'' ... in the EAP
conversation which are not necessary for chain building in this
authentication (i.e. "useless" root CAs).
If there is one or more of such CAs: add them to the trust relationship
as additional root CA.
With such a mechanism, the RADIUS/EAP server could drive every
connecting client towards the new trust anchor the next time a client
connects. The organisation would auto-update the trust base for all the
client devices which are active within days. So, if one knows the new
root CA with only a little advance notice, there can be a smooth transition.
Of course this doesn't help an organisation if the CA needs to change
*suddenly*, with no advance notice at all. I think that this is a really
rare corner case though.
This kind of convention is something that "we" as eduroam can't do on
our own. This needs a industry-wide buy-in across supplicants and is a
subject that would need to be taken up by standardisation/certification
bodies such as the Wi-Fi Alliance.
Which is not impossible.
Greetings,
Stefan Winter
Am 25.04.19 um 00:25 schrieb Martin Pauly:
> Hi all,
>
> as we all know, changing the root of a given CA is no fun.
> One reason for this is that with mobile devices, we hardly have
> any device management (MDM) at all (much like PCs in the 1990ies).
> Given that the use of CAT on most platforms involves the invocation
> of some piece of software: Couldn't we use this to implement some
> automatic check for updated profile settings on the server?
>
> So if e.g. the Android app installed some kind of cronjob/task that
> does a daily check for new .eapconfig profiles on cat.eduroam.org,
> would this work? IMHO, at the very least, the app could nag the user
> about the update or even go ahead and start the installation.
>
> My background is, of course, the current change of root cert for
> all German universities, affecting roughly 3 million people.
> Most of us use a cert fork which is easily prepared in Freeradius,
> but has to be triggered by the client using a special outer ID.
> Now everyone has to tell their thousands of clients that they
> should take action _before_ the root cert expires.
> This turns out a hard job because users simply don't care as long
> as things work. A little brat inside of the device might help
> the situation...
>
> I also see limits with this approach (e.g. Apple), but would it make
> sense at all?
>
> Cheers, Martin
>
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
Re: [[cat-users]] Feature Request: Have CAT apps look for profile updates?,
Stefan Winter, 07/11/2019
- Re: [[cat-users]] Feature Request: Have CAT apps look for profile updates?, Martin Pauly, 07/14/2019
Archive powered by MHonArc 2.6.19+.
