Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Checking for Name (CN) of Authentication Server

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Checking for Name (CN) of Authentication Server


Chronological Thread  
  • From: Stefan Winter <address@concealed>
  • To: address@concealed
  • Subject: Re: [[cat-users]] Checking for Name (CN) of Authentication Server
  • Date: Tue, 25 Feb 2020 08:52:55 +0100

Hello,

this is a recommendation we have on the eduroam wiki since a long time indeed:

https://wiki.geant.org/display/H2eduroam/EAP+Server+Certificate+considerations

(see the table, second entry)


And for the CAT property check, you mean, like the check that exists in CAT since several years?

https://github.com/GEANT/CAT/blob/release_2_0/core/diag/RADIUSTests.php#L261

Please run the CAT checks against the realm in question or let us know the realm so we can. If the check does not bark on this form of server name, we will need to check the code. The intention definitely is that you WILL be warned in these cases.

Greetings,

Stefan Winter


Am 24.02.20 um 17:44 schrieb Matthew Slowe:
Good $timezone,

Today I realised I had been a derp and set up a new eduroam service with a EAP Server Name along the lines of “CN=Organisation X eduroam Server”. All my testing was going fine up until I started using a real mobile device to try to use it configured via CAT… it just failed… iOS logged it as:

[eapttls_plugin.c:968] eapttls_verify_server(): server certificate not trusted status 1001 -9807

… even though rad_eap_test with, apparently, all the same pre-requisites on validation was fine.

Much gnashing of teeth later, I remembered someone had mentioned that some clients need the CN to be in FQDN format (and, possibly, for it to be actually valid). While I have nothing to cite for this, could a sanity check be added to the CAT admin sections to ensure that the "Name (CN) of Authentication Server” appears to be in the right format?

Thanks,
-- 
Matthew Slowe
Technical Specialist - Trust & Identity

Direct: 07442 097185
Team: 0300 300 2212, option 2
Lumen House, Library Avenue, Harwell Oxford, Didcot, OX11 0SG
 
Jisc Trust and Identity Services UK Access Management Federation - Assent - Certificate Service and Domain Registry

https://jisc.ac.uk/network/trust-and-identity






To unsubscribe, send this message: mailto:address@concealed?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users


Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19+.

Top of Page