cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: address@concealed
- Subject: Re: [[cat-users]] Checking for Name (CN) of Authentication Server
- Date: Tue, 25 Feb 2020 08:52:55 +0100
Hello,
this is a recommendation we have on the
eduroam wiki since a long time indeed:
(see the table, second entry)
And for the CAT property check, you
mean, like the check that exists in CAT since several years?
Please run the CAT checks against the
realm in question or let us know the realm so we can. If the check
does not bark on this form of server name, we will need to check
the code. The intention definitely is that you WILL be warned in
these cases.
Greetings,
Stefan Winter
Am 24.02.20 um 17:44 schrieb Matthew
Slowe:
Good $timezone,
Today I realised I had been a derp and set up a new
eduroam service with a EAP Server Name along the lines of
“CN=Organisation X eduroam Server”. All my testing was going
fine up until I started using a real mobile device to try to use
it configured via CAT… it just failed… iOS logged it as:
Technical Specialist - Trust
& Identity
Direct: 07442 097185
Team: 0300 300 2212, option 2
Lumen House, Library Avenue, Harwell Oxford, Didcot, OX11 0SG
Jisc Trust and Identity Services UK Access Management Federation - Assent - Certificate Service and Domain Registry
https://jisc.ac.uk/network/trust-and-identity
[eapttls_plugin.c:968] eapttls_verify_server(): server certificate not trusted status 1001 -9807
… even though rad_eap_test with, apparently, all
the same pre-requisites on validation was fine.
Much gnashing of teeth later, I remembered
someone had mentioned that some clients need the CN to be in
FQDN format (and, possibly, for it to be actually valid).
While I have nothing to cite for this, could a sanity check
be added to the CAT admin sections to ensure that the "Name
(CN) of Authentication Server” appears to be in the right
format?
Thanks,
--
Matthew SloweTeam: 0300 300 2212, option 2
Lumen House, Library Avenue, Harwell Oxford, Didcot, OX11 0SG
Jisc Trust and Identity Services UK Access Management Federation - Assent - Certificate Service and Domain Registry
To unsubscribe, send this message: mailto:address@concealed?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] Checking for Name (CN) of Authentication Server,
Matthew Slowe, 02/24/2020
-
Re: [[cat-users]] Checking for Name (CN) of Authentication Server,
Stefan Winter, 02/25/2020
- Re: [[cat-users]] Checking for Name (CN) of Authentication Server, Matthew Slowe, 02/25/2020
-
Re: [[cat-users]] Checking for Name (CN) of Authentication Server,
Stefan Winter, 02/25/2020
Archive powered by MHonArc 2.6.19+.
