Skip to Content.

cat-users - Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS


Chronological Thread 
  • From: Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>
  • To: Thorsten Fritsch <thorsten.fritsch AT unibas.ch>, Patrick Oberli <patrick.oberli AT ost.ch>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
  • Cc: Beate Deiss <beate.deiss AT unibas.ch>, Philipp Petermann <philipp.petermann AT unibas.ch>
  • Subject: Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS
  • Date: Tue, 18 May 2021 21:49:48 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=CnV/7jo3KDA06EGoQ+oLkKowpW5ThQcYuFnAw2O1Sek=; b=nAJ2i1vufYFZqPSuoRDS90TB80X7fy179/h/OJBhQ5K/ftMO4kq0/Fulevl7DiN/vxkKPPGHQuYkeM7GZgeUoENmZJuO53giNMeH5raXbZ+DI6Iqfrl8uBXCFKThtneO8gO7Hodq/aJzMOONzGcsopZCzYFc/R2jYyiKm1i6ZkWVWJla6lVBvnYm7qZ7DkNn0RvphoJhyBJtJpHZBZLOBlne/tVQZFqMIeNM9QLxFyrJUPELA93WFjt2MEmAh7LrcaS52jF7mcydz4n5ttZ5epHCaAeZNLWQzOj1yaMxfNiG9mGtzGkD6ec3IVObCf0VYfbx38//DfigXa3SQc8ZTw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=PCSt9IhU8fDD9HKIZxTR5BhnJvjvw8yxhj6QtagXlA6+lzAO8Y+udpIaF7DK6eYmP0+DH8G7cptfxHVVzH7XZLxpdxNJsILQUhsHPCs1O5JJxH0TkXayQPFE22hj2v1jCzeKP4G4bESgt61WY1zCt2Nas4jWG6Jt0tKkZ1eFYyHg8X7vVMAFuq2jsHFE7Fft9XA5vXO1jnhqtggKhjN3yZmuVBWrmns6M+xXyvECjT7MeO3V347Sy9HD84K+2EIg3QTh4u3yQhKXikonUmPGK2jWarAFZHcHMH/72JEd2j1gQKOA3zPwJO7QML58jUqPKPIBoZfFl3SU4PYeTmrBkQ==
  • Authentication-results: unibas.ch; dkim=none (message not signed) header.d=none;unibas.ch; dmarc=none action=none header.from=jisc.ac.uk;

Hi Thorsten,

Yes, geteduroam is now the preferred app on Android, because a) Swansea
University built the 'eduroam CAT' app and no longer actively develops it,
and b) 'eduroam CAT' on Android uses old API calls that are no longer
permitted on Android 11, so even if Swansea still supported 'eduroam CAT' on
Android, it wouldn't be allowed in the Google Play store anymore.

Also, geteduroam supports EAP-TLS if I remember correctly (through eduGAIN). (

If there are any issues with geteduroam, get in touch with the team!

Stefan Paetow
Federated Roaming Technical Specialist

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp AT jabber.dev.ja.net
skype: stefan.paetow.janet


In line with government advice, at Jisc we’re now working from home and our
offices are currently closed. Read our statement on coronavirus
<https://www.jisc.ac.uk/about/corporate/coronavirus-statement>.

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT No.
GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill,
Bristol, BS2 0JA. T 0203 697 5800.


On 17/05/2021, 06:41, "Thorsten Fritsch" <thorsten.fritsch AT unibas.ch> wrote:

Hi All,

thanks for your appreciated feedback. In my case I still had the same
issue with the geteduroam app (on Android 11) which
based on our CAT profile still deployed the PEAP config to the client.
Unfortunately, it would work only after manually changing from PEAP to
EAP-TTLS with MSCHAPv2.

As I haven't heard of the geteduroam app before I'm wondering if it's
trustworthy and safe to use it. Is this app commonly used by the
Swiss/European EDU community ?

Thanks and best,
Thorsten





-----Original Message-----
From: cat-users-request AT lists.geant.org
<cat-users-request AT lists.geant.org> On Behalf Of Patrick Oberli
Sent: Wednesday, 12 May 2021 08:42
To: Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>; cat-users AT lists.geant.org
Subject: RE: [[cat-users]] Specific CatInstaller for Android11 with
EAP-TTLS

Hi All

This is a very interesting discussion.
I had yesterday a Samsung A52 in the hand, where the owner told me he
received a system update yesterday morning and since then his eduroam
(manual) configuration stopped working. We use PEAP MSCHAPv2 here with public
signed certificates. In his case, it was not anymore possible to add the
eduroam profile manually and then authenticating. The Windows Radius always
complained about wrong username/password.
Once we used geteduroam to install the profile, it instantly worked.

Kind regards

ICT - IT-Infrastructure
Netzwerk- und Multimediateam
Patrick Oberli

Tel direkt: +41 58 257 4958
Email: patrick.oberli AT ost.ch

OST – Ostschweizer Fachhochschule
ICT Information & Communication Technology | Oberseestrasse 10 | 8640
Rapperswil | Switzerland | https://www.ost.ch

OST – Ostschweizer Fachhochschule ist der Zusammenschluss aus HSR
Rapperswil, FHS St.Gallen und NTB Buchs.

-----Original Message-----
From: cat-users-request AT lists.geant.org
<cat-users-request AT lists.geant.org> On Behalf Of Stefan Paetow
Sent: Dienstag, 11. Mai 2021 19:16
To: cat-users AT lists.geant.org
Subject: Re: [[cat-users]] Specific CatInstaller for Android11 with
EAP-TTLS

> > After googling around I found that In December 2020, the Android
11 QPR1 security disabled the ability to select “Do not validate” for the “CA
Certificate” dropdown in network settings for a given SSID and changed the
supplicant behaviour.
> ... and Samsung re-enabled (or still has) it, at least in a
Student's Galaxy A51 with Android 11 we set up last week.

Yes, Samsung shoehorned it into the certificate validation option (i.e.
'use system certs', 'use specific cert', or 'do not validate'). I can only
surmise that this must've come from somewhere for them to include it.

> IMO, the "Do not validate" setting has proven THE most dangerous
thing in eduroam.

Undoubtedly. As is technically the server cert pinning that iOS uses if
you do not use geteduroam or an MDM profile (as issued by eduroam CAT).

> I do not miss it, but you may need to set up MDM, an onboarding
network or local means of
> config transfer such aus USB-OTG, which may mean a lot of work.

Yes, many of our universities use an onboarding network, although many of
our colleges and schools don't.

> in most Samsung devices (with the notable exception of the
Galaxy S21).

Is it possible that the S21 has already received a fix for this issue? I
have a Samsung device here that did display the problem when I upgraded to
Android 11. I'll power it up and check whether it's getting any updates.

Stefan Paetow
Federated Roaming Technical Specialist

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp AT jabber.dev.ja.net
skype: stefan.paetow.janet


In line with government advice, at Jisc we’re now working from home and
our offices are currently closed. Read our statement on coronavirus
<https://www.jisc.ac.uk/about/corporate/coronavirus-statement>.

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT No.
GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill,
Bristol, BS2 0JA. T 0203 697 5800.


To unsubscribe, send this message:
mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link:
https://lists.geant.org/sympa/sigrequest/cat-users
To unsubscribe, send this message:
mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link:
https://lists.geant.org/sympa/sigrequest/cat-users





Archive powered by MHonArc 2.6.19.

Top of Page