Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS

cat-users AT

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS

Chronological Thread 
  • From: Stefan Paetow <Stefan.Paetow AT>
  • To: Thorsten Fritsch <thorsten.fritsch AT>, Patrick Oberli <patrick.oberli AT>, "cat-users AT" <cat-users AT>
  • Cc: Beate Deiss <beate.deiss AT>, Philipp Petermann <philipp.petermann AT>
  • Subject: Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS
  • Date: Tue, 18 May 2021 21:49:48 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; 1; spf=pass; dmarc=pass action=none; dkim=pass; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed;; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=CnV/7jo3KDA06EGoQ+oLkKowpW5ThQcYuFnAw2O1Sek=; b=nAJ2i1vufYFZqPSuoRDS90TB80X7fy179/h/OJBhQ5K/ftMO4kq0/Fulevl7DiN/vxkKPPGHQuYkeM7GZgeUoENmZJuO53giNMeH5raXbZ+DI6Iqfrl8uBXCFKThtneO8gO7Hodq/aJzMOONzGcsopZCzYFc/R2jYyiKm1i6ZkWVWJla6lVBvnYm7qZ7DkNn0RvphoJhyBJtJpHZBZLOBlne/tVQZFqMIeNM9QLxFyrJUPELA93WFjt2MEmAh7LrcaS52jF7mcydz4n5ttZ5epHCaAeZNLWQzOj1yaMxfNiG9mGtzGkD6ec3IVObCf0VYfbx38//DfigXa3SQc8ZTw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901;; cv=none; b=PCSt9IhU8fDD9HKIZxTR5BhnJvjvw8yxhj6QtagXlA6+lzAO8Y+udpIaF7DK6eYmP0+DH8G7cptfxHVVzH7XZLxpdxNJsILQUhsHPCs1O5JJxH0TkXayQPFE22hj2v1jCzeKP4G4bESgt61WY1zCt2Nas4jWG6Jt0tKkZ1eFYyHg8X7vVMAFuq2jsHFE7Fft9XA5vXO1jnhqtggKhjN3yZmuVBWrmns6M+xXyvECjT7MeO3V347Sy9HD84K+2EIg3QTh4u3yQhKXikonUmPGK2jWarAFZHcHMH/72JEd2j1gQKOA3zPwJO7QML58jUqPKPIBoZfFl3SU4PYeTmrBkQ==
  • Authentication-results:; dkim=none (message not signed) header.d=none;; dmarc=none action=none;

Hi Thorsten,

Yes, geteduroam is now the preferred app on Android, because a) Swansea
University built the 'eduroam CAT' app and no longer actively develops it,
and b) 'eduroam CAT' on Android uses old API calls that are no longer
permitted on Android 11, so even if Swansea still supported 'eduroam CAT' on
Android, it wouldn't be allowed in the Google Play store anymore.

Also, geteduroam supports EAP-TLS if I remember correctly (through eduGAIN). (

If there are any issues with geteduroam, get in touch with the team!

Stefan Paetow
Federated Roaming Technical Specialist

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp AT
skype: stefan.paetow.janet

In line with government advice, at Jisc we’re now working from home and our
offices are currently closed. Read our statement on coronavirus

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT No.
GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill,
Bristol, BS2 0JA. T 0203 697 5800.

On 17/05/2021, 06:41, "Thorsten Fritsch" <thorsten.fritsch AT> wrote:

Hi All,

thanks for your appreciated feedback. In my case I still had the same
issue with the geteduroam app (on Android 11) which
based on our CAT profile still deployed the PEAP config to the client.
Unfortunately, it would work only after manually changing from PEAP to

As I haven't heard of the geteduroam app before I'm wondering if it's
trustworthy and safe to use it. Is this app commonly used by the
Swiss/European EDU community ?

Thanks and best,

-----Original Message-----
From: cat-users-request AT
<cat-users-request AT> On Behalf Of Patrick Oberli
Sent: Wednesday, 12 May 2021 08:42
To: Stefan Paetow <Stefan.Paetow AT>; cat-users AT
Subject: RE: [[cat-users]] Specific CatInstaller for Android11 with

Hi All

This is a very interesting discussion.
I had yesterday a Samsung A52 in the hand, where the owner told me he
received a system update yesterday morning and since then his eduroam
(manual) configuration stopped working. We use PEAP MSCHAPv2 here with public
signed certificates. In his case, it was not anymore possible to add the
eduroam profile manually and then authenticating. The Windows Radius always
complained about wrong username/password.
Once we used geteduroam to install the profile, it instantly worked.

Kind regards

ICT - IT-Infrastructure
Netzwerk- und Multimediateam
Patrick Oberli

Tel direkt: +41 58 257 4958
Email: patrick.oberli AT

OST – Ostschweizer Fachhochschule
ICT Information & Communication Technology | Oberseestrasse 10 | 8640
Rapperswil | Switzerland |

OST – Ostschweizer Fachhochschule ist der Zusammenschluss aus HSR
Rapperswil, FHS St.Gallen und NTB Buchs.

-----Original Message-----
From: cat-users-request AT
<cat-users-request AT> On Behalf Of Stefan Paetow
Sent: Dienstag, 11. Mai 2021 19:16
To: cat-users AT
Subject: Re: [[cat-users]] Specific CatInstaller for Android11 with

> > After googling around I found that In December 2020, the Android
11 QPR1 security disabled the ability to select “Do not validate” for the “CA
Certificate” dropdown in network settings for a given SSID and changed the
supplicant behaviour.
> ... and Samsung re-enabled (or still has) it, at least in a
Student's Galaxy A51 with Android 11 we set up last week.

Yes, Samsung shoehorned it into the certificate validation option (i.e.
'use system certs', 'use specific cert', or 'do not validate'). I can only
surmise that this must've come from somewhere for them to include it.

> IMO, the "Do not validate" setting has proven THE most dangerous
thing in eduroam.

Undoubtedly. As is technically the server cert pinning that iOS uses if
you do not use geteduroam or an MDM profile (as issued by eduroam CAT).

> I do not miss it, but you may need to set up MDM, an onboarding
network or local means of
> config transfer such aus USB-OTG, which may mean a lot of work.

Yes, many of our universities use an onboarding network, although many of
our colleges and schools don't.

> in most Samsung devices (with the notable exception of the
Galaxy S21).

Is it possible that the S21 has already received a fix for this issue? I
have a Samsung device here that did display the problem when I upgraded to
Android 11. I'll power it up and check whether it's getting any updates.

Stefan Paetow
Federated Roaming Technical Specialist

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp AT
skype: stefan.paetow.janet

In line with government advice, at Jisc we’re now working from home and
our offices are currently closed. Read our statement on coronavirus

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT No.
GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill,
Bristol, BS2 0JA. T 0203 697 5800.

To unsubscribe, send this message:
mailto:sympa AT
Or use the following link:
To unsubscribe, send this message:
mailto:sympa AT
Or use the following link:

Archive powered by MHonArc 2.6.19.

Top of Page