cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <stefan.winter AT restena.lu>
- To: cat-users AT lists.geant.org
- Subject: Re: [[cat-users]] Radius certificate length and faq
- Date: Fri, 15 Oct 2021 11:29:55 +0200
Hello,
as Paul has already answered
extensively: our current advice regarding CAs, certificate
properties, key lengths etc. is on this page:
As Paul mentions the landscape of pros
and cons is shifting as devices and their OSes change (I would say
"evolve" but it isn't always a step in the right direction ;-) )
so some of the arguments in that page need to be re-weighted.
Still, if you read all that to the end, then you can make an
informed decision.
Personally, I think people often
underestimate how hard it is properly run a private CA long-term
and securely, so the final advice on the page "if you know what
you are doing, then use a private CA" should more often lead to
using a public CA than it actually does.
Greetings,
Stefan Winter
Am 14.10.21 um 18:06 schrieb Ricardo
Stella:
These may be questions for the eduroam admin list but it
does involve cat.
Few questions now...
* How long should the radius cert be? I understand that
renewing it won't affect cat since what matters is the root
that signs it. But reading iOS does not trust certs longer
than about 2 years, would this be the case? Should I plan on
renewing the radius cert every year? Would it be an issue with
the long term CA installed by cat?
* Are there any FAQs on verifying what extensions are
needed/required?
* We have a 3 node clearpass implementation. Should each
radius cert be its own CN but add all 3 nodes to subject alt
names?
I'll probably think of more questions once I hit send but
for now..
Thanks in advance - Ricardo.
--
°(((=((===°°°(((================================================
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users
Attachment:
OpenPGP_signature
Description: OpenPGP digital signature
- [[cat-users]] Radius certificate length and faq, Ricardo Stella, 10/14/2021
- Re: [[cat-users]] Radius certificate length and faq, Paul Dekkers, 10/14/2021
- Re: [[cat-users]] Radius certificate length and faq, Stefan Winter, 10/15/2021
Archive powered by MHonArc 2.6.19.