Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Using InCommon certificates

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Using InCommon certificates


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: Ricardo Stella <address@concealed>, address@concealed
  • Subject: Re: [[cat-users]] Using InCommon certificates
  • Date: Fri, 14 Feb 2020 09:18:52 +0100

Hello,


> We have a eduroam setup in test mode and am looking at using the CAT
> tool. My question revolves around the intermediate and root certificates.
>
> My understanding is that the radius certs renewal won't affect the end
> users, as long as they are issued by the same intermediate/root certs.
> So I need to make sure the intermediates and roots don't expire any
> time soon, right? If they do, users would have to download a new
> version with the new certificates, right?


That's almost entirely correct.


The root needs to stay the same.


The intermediate can change, but some extra caution has to be applied in
that case: the EAP server needs to send the new intermediate along with
its server cert as a partial chain then, because clients do not possess
the intermediate locally.


It is usually considered good practice to always send the intermediate
anyway, so it's not a big deal. Just something to be and remain aware of.


Greetings,


Stefan Winter


--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la
Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the recipient's
key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66


Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page