cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Ricardo Stella <stella AT rider.edu>
- To: cat-users AT lists.geant.org
- Subject: [[cat-users]] Radius certificate length and faq
- Date: Thu, 14 Oct 2021 12:06:45 -0400
These may be questions for the eduroam admin list but it does involve cat.
Few questions now...
* How long should the radius cert be? I understand that renewing it won't affect cat since what matters is the root that signs it. But reading iOS does not trust certs longer than about 2 years, would this be the case? Should I plan on renewing the radius cert every year? Would it be an issue with the long term CA installed by cat?
* Are there any FAQs on verifying what extensions are needed/required?
* We have a 3 node clearpass implementation. Should each radius cert be its own CN but add all 3 nodes to subject alt names?
I'll probably think of more questions once I hit send but for now..
Thanks in advance - Ricardo.
--
°(((=((===°°°(((================================================
- [[cat-users]] Radius certificate length and faq, Ricardo Stella, 10/14/2021
- Re: [[cat-users]] Radius certificate length and faq, Paul Dekkers, 10/14/2021
- Re: [[cat-users]] Radius certificate length and faq, Stefan Winter, 10/15/2021
Archive powered by MHonArc 2.6.19.