cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Patrick Oberli <patrick.oberli AT ost.ch>
- To: Andrea Delise <delise AT sissa.it>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Subject: RE: [[cat-users]] Multiple CA - Android
- Date: Mon, 7 Dec 2020 07:52:19 +0000
- Accept-language: en-CH, de-CH, en-US
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ost.ch; dmarc=pass action=none header.from=ost.ch; dkim=pass header.d=ost.ch; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=tVCm34L0mmn8WUicXkFOaEqmM1UOYgMgIwIQhyJiiW4=; b=jdEHGvtoM6BprXGashzVSsPFoQK08PEwipkiZ1nyslD9MOmtYauClc4O/DiO4fJhKC8wMVNd+7JXvfgckwcfMfrrtH6G3lr/ZBnHKG0GnUeMeGsuKNxRa8NTYc+cWo3YHbEnXmw5aIeOu5X7VdXI3HX5vT5NZpNDxdOi+ZzkNUWkVVlmRG6aQwC/UM3rdSAQAwYtCHWm1AI1SESY5rP7beUSl4DGHjhOO6hlFxylXIM92GCfqzsoIPT0+S6gfYniVo8xr27TB8S2hi1Iv8pqxVRNAmCjXa2k0Dm9sU83Qh10noa4NSZ/R975NPYS90PC65hn+cqX22DLfwu9wUu2bw==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=b/at4M77Ly8N6ulLrnZsME/z5FyYSgn0yec5KJYSmqNlUPW5/Gj2T8HGX2txs8T1WCfA0kMALp6JhPsgtmFjONOlgHhWxRSPdtWasqHAQtRSwOX2I5NMI44Z7+fn4oTOf3iZI4hV2V6XRctUDrWkSRAr7wbWAcAvAGwLurLdLSL8W/O00hAYyJyzwFFMnC+BGAjj2JfptBmKiAXDD6uqKd4S5RNFCALYJeosVuhCH6AgMNAFkm4xnLgBQMNlQNzBEqO7Y7qe2vlUjdRRC+MiHepSArQFKcYSscbXHgkFLBBSMkpqbqeMuhUJiBx/9VNwtOTVU1Be/ZJ6DZEJXQ+nrA==
- Authentication-results: sissa.it; dkim=none (message not signed) header.d=none;sissa.it; dmarc=none action=none header.from=ost.ch;
Hello Andrea
For Android > 9 we don't anymore use the CAT installer in our university,
because Android finally accepts a domain name to validate for the
certificates. Thanks to this you don't anymore have to install the
certificate or select "don't validate certificate".
This is of course only a workaround for the issue you are seeing.
In your case, do you have the certificate installed on all Radius Servers
(for that SSID) and also set as the active certificate? I have seen such a
behavior if different certificates are being used, but not issued by the same
CA.
Kind regards
ICT - IT-Infrastructure
Netzwerk- und Multimediateam
Patrick Oberli
Tel direkt: +41 58 257 4958
Email: patrick.oberli AT ost.ch
OST – Ostschweizer Fachhochschule
ICT Information & Communication Technology | Oberseestrasse 10 | 8640
Rapperswil | Switzerland | https://www.ost.ch
OST – Ostschweizer Fachhochschule ist der Zusammenschluss aus HSR Rapperswil,
FHS St.Gallen und NTB Buchs.
-----Original Message-----
From: cat-users-request AT lists.geant.org <cat-users-request AT lists.geant.org>
On Behalf Of Andrea Delise
Sent: Montag, 7. Dezember 2020 08:35
To: cat-users AT lists.geant.org
Subject: [[cat-users]] Multiple CA - Android
Hi everybody,
I'm Andrea Delise, one of the cat (and eduroam) administrators for SISSA, an
Italian university. Since Terena has changed the certificate provider, we are
working on the rollout of the new CA. We are on a fairly tight schedule, we
didn't plan ahead to get the last certificate from the previuous CA.
According to the documentation:
https://wiki.geant.org/display/H2eduroam/A+guide+to+eduroam+CAT+for+IdP+administrators#AguidetoeduroamCATforIdPadministrators-Note3-CArolloversupport
for Android greater or equal to 7.1 everything should go fine. For all the
other OS (or at least the ones I tested) it went fine.
However, from my quick tests, a device with a rather vanilla Android 9.0 (my
own device, an Asus Zenfone Max Pro M1) was unable to authenticate with the
new CA, accepting certificates only from the old CA. Due to the COVID
restrictions and the lack of colleagues with testing devices, I wasn't able
to perform more extensive tests (but a Xiaomi with Android
10 worked ok, while a Samsung with Android 10 showed the failed screen lock
detection bug discussed in another conversation).
What's your experience? Did I get an "unlucky" device or is the Android
version threshold different (7.1 or 10)?
Thank you and best regards,
Andrea Delise
______________________________________________
Andrea Delise
tel: +39-040-3787537 e-mail: delise AT sissa.it SISSA Information Technology
and Computing Services http://www.itcs.sissa.it via Bonomea 265 - I 34136
Trieste - Italy
To unsubscribe, send this message:
mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users
- [[cat-users]] Multiple CA - Android, Andrea Delise, 12/07/2020
- RE: [[cat-users]] Multiple CA - Android, Patrick Oberli, 12/07/2020
- Re: [[cat-users]] Multiple CA - Android, Paul Dekkers, 12/07/2020
- Re: [[cat-users]] Multiple CA - Android, Andrea Delise, 12/07/2020
- Re: [[cat-users]] Multiple CA - Android, Paul Dekkers, 12/07/2020
- Re: [[cat-users]] Multiple CA - Android, Andrea Delise, 12/10/2020
- Re: [[cat-users]] Multiple CA - Android, Paul Dekkers, 12/10/2020
- Re: [[cat-users]] Multiple CA - Android, Andrea Delise, 12/11/2020
- Re: [[cat-users]] Multiple CA - Android, Paul Dekkers, 12/10/2020
- Re: [[cat-users]] Multiple CA - Android, Andrea Delise, 12/10/2020
- Re: [[cat-users]] Multiple CA - Android, Paul Dekkers, 12/07/2020
- Re: [[cat-users]] Multiple CA - Android, Andrea Delise, 12/07/2020
Archive powered by MHonArc 2.6.19.