Skip to Content.

cat-users - Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS


Chronological Thread 
  • From: Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>
  • To: "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
  • Subject: Re: [[cat-users]] Specific CatInstaller for Android11 with EAP-TTLS
  • Date: Thu, 20 May 2021 10:26:46 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=JgBqs4SsSBMuvraVB6VoJrzgc8wnxXGCutEyN/H2V0Q=; b=W1PcsMWWc3NhS4CurJDbQlcxXeIKTFYzELKEPfYas/uLkGs1bjawaXXY7pzSMJIbyhEc+f5AV8A8gKOfPBeBZV5lRuoWe5fJ58vZL0VdGCgIFmWC7uwf3lFPolA3HEAKC4MjWNyp7chwZrKHMSiKHMVSsfQdsyz2Y2SFFIh/SwpPGCrDkcbuK2LLxGNhHUt/I0ex7ZB+qD61/bNlVtdU06sba89Wct0dihtGrIg14SBny4SjWko0kD+oMN1EmtAihGEURvJtdiZh7fJ6lLHx3ux8r7PxQV4rjSCqSXasN9MF771Q+xvCkVw9Ch9sDc4F4xTZHFdQW463v+NuOHN65A==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=UqffsCC0FwK9SsOU11VOXkgL8YF0nOZLJw5fn2631T8q0n7yNB+NSvsuhSE3iyBdWTO395bhFri0d4ZP6V4S9ujx25ju0gNH1eBrVM9yI0v8NtHHdNZLD/JVtMdES4FmCgFGvS+78GkPeH5tiJLyfs1qZgG7SPvi5D3svrEK3RN+S7bJCDTWPLwShE6OHb65Y6uWJt2E3ryJbZJKLz7yAfnv+kXMzX8e3t6w5ekdNS5x3aF5hqt2TauZJR5B1zwqSjYsrvXUqeOpQ9DWFx0QzFhxTPNAa8ky9k8aUstKN5Lgg3XhBdjchFMKe0TCZopEPLDyVJ+U5NAri1amSX7hsw==
  • Authentication-results: lists.geant.org; dkim=none (message not signed) header.d=none;lists.geant.org; dmarc=none action=none header.from=jisc.ac.uk;

Hi Martin,

> This must be an effect of the specific MDM. With Sophos MDM, we once
> applied
> the same client cert to 120 iPads for a WiFi test with that many devices.
> The EAP-TLS worked, the WiFi test failed at that time, and the project
> was
> abandoned.

Entirely possible.

> I am curious to see the concepts behind Let's Wifi of geteduroam.
> But no matter how good they are, it will at least take 2 years
> before we will be able to invest any significant effort there.
> In the mean time we will continue to require an anonymous outer ID
> from our users (and hope there will be no more things like EAP-Success
> bug).

Indeed. Worth having a chat to UNINETT who were/are behind the original idea
of geteduroam, sooo...

> Just an academic question: If you had a mobile OS landscape all
> capable of EAP-PWD and only allow this in the server, would you
> be able to achieve the same level of security as with EAP-TLS?

I have no idea... I am but a system admin, not someone with extensive
academic research expertise.

:-)

Stefan Paetow
Federated Roaming Technical Specialist

t: +44 (0)1235 822 125
gpg: 0x3FCE5142
xmpp: stefanp AT jabber.dev.ja.net
skype: stefan.paetow.janet


In line with government advice, at Jisc we’re now working from home and our
offices are currently closed. Read our statement on coronavirus
<https://www.jisc.ac.uk/about/corporate/coronavirus-statement>.

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT No.
GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill,
Bristol, BS2 0JA. T 0203 697 5800.





Archive powered by MHonArc 2.6.19.

Top of Page