Skip to Content.

cat-users - RE: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


RE: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS


Chronological Thread 
  • From: Patrick Oberli <patrick.oberli AT ost.ch>
  • To: Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
  • Subject: RE: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS
  • Date: Wed, 12 May 2021 06:41:53 +0000
  • Accept-language: en-CH, de-CH, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ost.ch; dmarc=pass action=none header.from=ost.ch; dkim=pass header.d=ost.ch; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=GFmcf6MoZaWb6K4wUuQWz+hEvb6UL1+gp/M0/rcW9uw=; b=a8q/EJ4eYWdZdopTfASo8jOF8EahnsMZUmTskiyjzS7DPolRsFGxqKd5qraM7p0cNPvk/zti9OmKk3Q5dhI2hnhhAXn81g68kZc4y38Hpmb4Q7PTEG0hV4/f0+/JgPy5mU7JK6r5sSMVVx8yjzXBo7zrUvvYN7ND61O+0tAbvHTcZ+aLnc6c6+6mPRw8Ua+baMAVwwbZyFQeobA+oSCS/QDYGthOljbf4viD2cN+0MShYZWdFplZ8ykYTRWGTK9tFN8odkN8BcwG7CrXl7SkNnnVTnElbZsXdDAVi6yWy7I3ZFuZGew9bORKzrcqKGkjwPtEw4j8j0E22GMaOzUuMw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=n5ASp/vWtUNHUdZf05PUunrPpkjMZ//X/J+qKM+3mfggclnbrfdnyKEVIllr9BfnZ5qOOLgNaYYbIdc+ReUVoyodi8E+01J6MFL21Ugw1UdnQGFg5/8QZ6glbCfotvani+pVsMFu3R4ScIMDG5a0+hC8Gk8Dr/PUkRx+x+xCBCVRiFQpbZfLDSQOlhbiTn3mLZUqXegiQvrvvBaXP5sG6FKYkim0GUTUGEQ7VaZqU0yxDl+gs6eWH6pvFPD7ZIchmY9uCO/mx7Omh4n4zL1aPxbTt6u7TCmVoSg9CPNRKiUOzQyxGvaMNIkpO/M+DNk5TjAlKQCNx4lBzRArAyNy4w==
  • Authentication-results: jisc.ac.uk; dkim=none (message not signed) header.d=none;jisc.ac.uk; dmarc=none action=none header.from=ost.ch;

Hi All

This is a very interesting discussion.
I had yesterday a Samsung A52 in the hand, where the owner told me he
received a system update yesterday morning and since then his eduroam
(manual) configuration stopped working. We use PEAP MSCHAPv2 here with public
signed certificates. In his case, it was not anymore possible to add the
eduroam profile manually and then authenticating. The Windows Radius always
complained about wrong username/password.
Once we used geteduroam to install the profile, it instantly worked.

Kind regards

ICT - IT-Infrastructure
Netzwerk- und Multimediateam
Patrick Oberli

Tel direkt: +41 58 257 4958
Email: patrick.oberli AT ost.ch

OST – Ostschweizer Fachhochschule
ICT Information & Communication Technology | Oberseestrasse 10 | 8640
Rapperswil | Switzerland | https://www.ost.ch

OST – Ostschweizer Fachhochschule ist der Zusammenschluss aus HSR Rapperswil,
FHS St.Gallen und NTB Buchs.

-----Original Message-----
From: cat-users-request AT lists.geant.org <cat-users-request AT lists.geant.org>
On Behalf Of Stefan Paetow
Sent: Dienstag, 11. Mai 2021 19:16
To: cat-users AT lists.geant.org
Subject: Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS

> > After googling around I found that In December 2020, the Android 11
> QPR1 security disabled the ability to select “Do not validate” for the “CA
> Certificate” dropdown in network settings for a given SSID and changed the
> supplicant behaviour.
> ... and Samsung re-enabled (or still has) it, at least in a Student's
> Galaxy A51 with Android 11 we set up last week.

Yes, Samsung shoehorned it into the certificate validation option (i.e. 'use
system certs', 'use specific cert', or 'do not validate'). I can only surmise
that this must've come from somewhere for them to include it.

> IMO, the "Do not validate" setting has proven THE most dangerous
> thing in eduroam.

Undoubtedly. As is technically the server cert pinning that iOS uses if you
do not use geteduroam or an MDM profile (as issued by eduroam CAT).

> I do not miss it, but you may need to set up MDM, an onboarding
> network or local means of
> config transfer such aus USB-OTG, which may mean a lot of work.

Yes, many of our universities use an onboarding network, although many of our
colleges and schools don't.

> in most Samsung devices (with the notable exception of the Galaxy
> S21).

Is it possible that the S21 has already received a fix for this issue? I have
a Samsung device here that did display the problem when I upgraded to Android
11. I'll power it up and check whether it's getting any updates.

Stefan Paetow
Federated Roaming Technical Specialist

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp AT jabber.dev.ja.net
skype: stefan.paetow.janet


In line with government advice, at Jisc we’re now working from home and our
offices are currently closed. Read our statement on coronavirus
<https://www.jisc.ac.uk/about/corporate/coronavirus-statement>.

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT No.
GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill,
Bristol, BS2 0JA. T 0203 697 5800.


To unsubscribe, send this message:
mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users



Archive powered by MHonArc 2.6.19.

Top of Page