cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Daniel Sheppard <da.sheppard AT uwinnipeg.ca>
- To: Tomasz Wolniewicz <twoln AT umk.pl>, "Stevens, Andy" <andy.stevens AT wur.nl>, Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>, darren.wheatcroft <darren.wheatcroft AT NOTTINGHAM.AC.UK>
- Subject: RE: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error
- Date: Thu, 23 Dec 2021 14:37:29 +0000
- Accept-language: en-US
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=uwinnipeg.ca; dmarc=pass action=none header.from=uwinnipeg.ca; dkim=pass header.d=uwinnipeg.ca; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=sFW9AM3iwMLrTNQdMiPP142OJQvPatFHsvgcV8R2+eE=; b=B8lLrpY129YQlBvorb9rlXmMVRsm/U6yoEVabZhRcUuoqZdRcoCjx9dzYajWLtcNShU6+EFVNo/K/YQxuctusbl6QfWX3zSfip4GXbfs9F1PtrmYVJcf61b76RrHiteoTJRtsJ974b1JIIzCI9akCnvtXdwEYhlYf1k9Rtc1lpzJaxIqdbfzzRiiS3YhUr1vM/fMmZJ+5eHC5tQCEN22Jb8JQJPXrf4/63DXW7Irz+46dVN8Gf6XwMYRHemFjnmruZdq8Y4QLkrlIAO8YzKsFPryA1a1zNqDr/hiEpk72S1hHfFS9miHdrMDsigMVAJqiDrMcTf1XBHNhaZBxw6g8g==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cXSaSLyc9y+KBZoHJFjFfGIAMY0CY4pctcT657m8yaySkwVrEbjkqcoE6dhIOQJ0tmP9iJYOT6opSERp3/tsaokib9IR4jMeRFEPJ1bzn1pQ4AYybx7PzlXT2wmJgXa9LanoxH6bqvcj/NSQ4phneBxiELWmg/y+n0DUC/PJpAaeIlzwItWyDsnwlO5ZzWgtHA+IaE1xeDBTry8ThtlcSZsIUlCG1BNTewR0nfWT7uO9k7aBn9fq0pc8ffFphTqXo4ddK/fbhWHXyKjn2yeqZk/XsrpP6B1lgKeFbXHqjDIK4RcLzJn0mRLRfwhGNqwbJTu+t19hM0LXIcQK4mYFlw==
- Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=uwinnipeg.ca;
Including the intermediate allows for a minor optimization as the supplicant does not need to contact the server to request the intermediate as part of the TLS handshake.
From: cat-users-request AT lists.geant.org <cat-users-request AT lists.geant.org>
On Behalf Of Tomasz Wolniewicz
I am not sure if I correctly interpret your question. Any EAP client needs to *know* the root to be able to decide that the server cert not only has the correct name but also that it originates form the trusted source. If the root is already in the Windows trust store then the only use that the installer makes of it is pointing to its fingerprint as *the root*. The intermediate certificates normally should not be needed. It should be up to the RADIUS server to send out all intermediates together with the server certificate. The client is then able to verify the whole path (using the root that it has locally). If the server does not send the chain then the client needs to have the intermediates for verification. Cheers Tomasz Wolniewicz
W dniu 22.12.2021 o 17:27, Stevens, Andy pisze:
-- Tomasz Wolniewicz twoln AT umk.pl http://www.home.umk.pl/~twoln Uniwersyteckie Centrum Informatyczne Information&Communication Technology Centre Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University, pl. Rapackiego 1, Torun pl. Rapackiego 1, Torun, Poland tel: +48-56-611-2750; tel kom.: +48-693-032-576 To unsubscribe, send this message:
mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users |
- [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Stefan Winter, 12/21/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Stefan Winter, 12/21/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Stefan Paetow, 12/22/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Stevens, Andy, 12/22/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Tomasz Wolniewicz, 12/23/2021
- RE: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Daniel Sheppard, 12/23/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Tomasz Wolniewicz, 12/23/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Stevens, Andy, 12/22/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Stefan Paetow, 12/22/2021
- Re: [[cat-users]] Fwd: Windows 10 & CAT - TLS Session reuse error, Stefan Winter, 12/21/2021
Archive powered by MHonArc 2.6.19.