Skip to Content.

cat-users - Re: [[cat-users]] Long shot, but trying to get an old Apple TV to work with eduroam

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


Re: [[cat-users]] Long shot, but trying to get an old Apple TV to work with eduroam


Chronological Thread 
  • From: Stefan Paetow <Stefan.Paetow AT jisc.ac.uk>
  • To: "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
  • Subject: Re: [[cat-users]] Long shot, but trying to get an old Apple TV to work with eduroam
  • Date: Wed, 16 Aug 2023 13:48:28 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=y4XuCJiOI4qaNeNKx62e5jkL36z2Ivf8+UF6jj2b408=; b=XhQWPJ0e7orSQuSsa2mX+7Euwuq3/7lj7B4JowKz9jk3+FSKliQYbKiye+rlPN276zRePRm/YoS56hOsP03gln86H/6rqqPpXb6pXmcLxwKQ/gSf7hJ3TIi6WYqgvMRL70uoDg/j9dF4OikhxWNZJogUwb9h+xEdWbiHVHPJo+vLOfbjTQkSJKCSRxHAfIYITcYgEKE5zeyNX7s4+j//a4ip+3QG++Y2oaK46zMUHzapaYbCPFBUGBsxE3hfhtfA79YUbE4XEhy7/nlxUTXmGqPFlJWww5UAwDlX6H93P0y+QCs1uXEbYj42kminI1GbF7KL4W6aHd2WGgyBlYltLQ==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=VZ7hSSXkoq+Ws5Vxhy6a/JVVLFYJF5ujAChk+G1i1N4QFZJTYq7jEminjCodQKdaWbSy77xT12UCEigjS+doViQUhPViC+HvAfXa8Th++iKSdjO4O9Kkz3IV1DeebrzkcaItM7yzGJYh6u9L8a/Nkr0mVe5gMejN879SpAxe2xFLDNaaRHOhCnBBjuBgaeQwSZ/fkiNgh9g6AtShr1SRXF/rIM1cRzzRYyZfKkj2CKBO219fb1yvSB47G+USTkUSzySY2r6ib1+is2PxWmL7i0jyx6IVLJc4PU8VcdI0ISODR626s753BE8wDHpGHLuba/8eRK9BSJBsdFSDVVKphQ==
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=jisc.ac.uk;

Hi Tomasz,

That's quite possible. We'll have a look into that.

:-)

Stefan Paetow
Federated Roaming Technical Specialist
eduroam(UK), Jisc

email/teams: stefan.paetow AT jisc.ac.uk
gpg: 0x3FCE5142

For eduroam support, please contact the eduroam team via help AT jisc.ac.uk and
mark it for eduroam’s attention.
On Wednesdays and Fridays, I am not available between 12:00 and 15:00.

jisc.ac.uk

Jisc is a registered charity (number 1149740) and a company limited by
guarantee which is registered in England under Company No. 5747339, VAT No.
GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1
6NB Tel: 020 3697 5800.





On 16/08/2023, 12:23, "cat-users-request AT lists.geant.org
<mailto:cat-users-request AT lists.geant.org> on behalf of Tomasz Wolniewicz"
<cat-users-request AT lists.geant.org <mailto:cat-users-request AT lists.geant.org>
on behalf of cat-users AT lists.geant.org <mailto:cat-users AT lists.geant.org>>
wrote:


Would this TV accept TLS credentials? If so then hostedIdP could be an
answer. Also you could ask some friendly soul with access to a web
signing certificate to sigh the profile for you. Apple does not require
software signing certificates, so any will do. The signature is just a
simple S/MIME.


The lime below is copied form the signer-template in CAT:


openssl smime -sign -signer "$MY_PATH/$PUBKEY" -inkey
"$MY_PATH/$PRIVKEY" $passin -certfile "$MY_PATH/$CA_CHAIN" -nodetach
-outform der -in $1 -out $2


Cheers


Tomasz






W dniu 16.08.2023 o 12:10, Stefan Paetow (via cat-users Mailing List) pisze:
> Just an update on this:
>
> Dick and I collaborated on this, and it's since been clarified that older
> Apple TVs will need a mobileconfig file that contains the user credentials.
> This of course means that it is then turned into an unsigned profile.
> Investigation is still on-going :-)
>
> Stefan Paetow
> Federated Roaming Technical Specialist
> eduroam(UK), Jisc
>
> email/teams: stefan.paetow AT jisc.ac.uk <mailto:stefan.paetow AT jisc.ac.uk>
> gpg: 0x3FCE5142
>
> For eduroam support, please contact the eduroam team via help AT jisc.ac.uk
> <mailto:help AT jisc.ac.uk> and mark it for eduroam’s attention.
> On Wednesdays and Fridays, I am not available between 12:00 and 15:00.
>
> jisc.ac.uk
>
> Jisc is a registered charity (number 1149740) and a company limited by
> guarantee which is registered in England under Company No. 5747339, VAT No.
> GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1
> 6NB Tel: 020 3697 5800.
>
>
>
>
>
> On 14/08/2023, 21:44, "cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>> on behalf of Stefan Paetow"
> <cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>> on behalf of
> cat-users AT lists.geant.org <mailto:cat-users AT lists.geant.org>
> <mailto:cat-users AT lists.geant.org <mailto:cat-users AT lists.geant.org>>>
> wrote:
>
>
> Hi Dick,
>
>
> It looks like an option to use EAP-FAST is not expected to be in there,
> more specifically, this option: EAPFastProvisionPACAnonymously.
>
>
> If that gets removed, then it's quite possible it'll load ok.
>
>
> :-)
>
>
> Stefan Paetow
> Federated Roaming Technical Specialist
> eduroam(UK), Jisc
>
>
> email/teams: stefan.paetow AT jisc.ac.uk <mailto:stefan.paetow AT jisc.ac.uk>
> <mailto:stefan.paetow AT jisc.ac.uk <mailto:stefan.paetow AT jisc.ac.uk>>
> gpg: 0x3FCE5142
>
>
> For eduroam support, please contact the eduroam team via help AT jisc.ac.uk
> <mailto:help AT jisc.ac.uk> <mailto:help AT jisc.ac.uk <mailto:help AT jisc.ac.uk>>
> and mark it for eduroam’s attention.
> On Wednesdays and Fridays, I am not available between 12:00 and 15:00.
>
>
> jisc.ac.uk
>
>
> Jisc is a registered charity (number 1149740) and a company limited by
> guarantee which is registered in England under Company No. 5747339, VAT No.
> GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1
> 6NB Tel: 020 3697 5800.
>
>
>
>
>
>
>
>
>
>
> On 14/08/2023, 21:24, "cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>>> on behalf of Dick Visser"
> <cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>
> <mailto:cat-users-request AT lists.geant.org
> <mailto:cat-users-request AT lists.geant.org>>> on behalf of
> cat-users AT lists.geant.org <mailto:cat-users AT lists.geant.org>
> <mailto:cat-users AT lists.geant.org <mailto:cat-users AT lists.geant.org>>
> <mailto:cat-users AT lists.geant.org <mailto:cat-users AT lists.geant.org>
> <mailto:cat-users AT lists.geant.org <mailto:cat-users AT lists.geant.org>>>>
> wrote:
>
>
>
>
> Hii
>
>
>
>
> I have an Apple TV 3rd gen, A1469, that I would like to connect to
> eduroam. By connecting it to the Configurator app on macOS, through an
> USB data cable, I have the possibility to add a profile. I download
> that from cat.eduroam.org, and add it. Things seem to go ahead
> but they fail after a few seconds. The Configurator app can retrieve
> logs, and they say this:
>
>
>
>
> Aug 14 11:13:00 Apple-TV mc_mobile_tunnel[97] <Notice>: (Note ) MC:
> mc_mobile_tunnel starting.
> Aug 14 11:13:02 Apple-TV mobile_installation_proxy[96] <Error>:
> 0x405000 handle_connection: Could not receive request from host.
> Aug 14 11:13:04 Apple-TV mc_mobile_tunnel[97] <Notice>: (Note ) MC:
> Escalation accepted.
> Aug 14 11:13:04 Apple-TV mc_mobile_tunnel[97] <Notice>: (Note ) MDM:
> Attempting to perform Supervised request: ProceedWithKeybagMigration
> Aug 14 11:13:04 Apple-TV mc_mobile_tunnel[97] <Notice>: (Note ) MDM:
> Attempting to perform Supervised request: ProfileList
> Aug 14 11:13:04 Apple-TV mc_mobile_tunnel[97] <Notice>: (Note ) MDM:
> Handling request type: ProfileList
> Aug 14 11:13:04 Apple-TV mc_mobile_tunnel[97] <Notice>: (Note ) MDM:
> Attempting to perform Supervised request: InstallProfileSilent
> Aug 14 11:13:04 Apple-TV mc_mobile_tunnel[97] <Notice>: (Warn ) MC:
> Payload “eduroam® - SSID eduroam” contains unexpected fields in EAP
> Configuration. They are: <CFBasicHash 0x15dc4ba0 [0x368a98d0]>{type =
> mutable dict, count = 1,
> entries =>
> 1 : <CFString 0x15dc06b0 [0x368a98d0]>{contents =
> "EAPFastProvisionPACAnonymously"} = <CFBoolean 0x368a9ad8
> [0x368a98d0]>{value = false}
> }
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Note ) MC: Checking
> for MDM installation...
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Note ) MC:
> ...finished checking for MDM installation.
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Warn ) MC: Payload
> “eduroam® - SSID eduroam” contains unexpected fields in EAP
> Configuration. They are: <CFBasicHash 0x16db0950 [0x368a98d0]>{type =
> mutable dict, count = 1,
> entries =>
> 1 : <CFString 0x16dac580 [0x368a98d0]>{contents =
> "EAPFastProvisionPACAnonymously"} = <CFBoolean 0x368a9ad8
> [0x368a98d0]>{value = false}
> }
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Note ) MC: Beginning
> profile installation...
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Error) MC: Rolling
> back installation of profile
> “org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>>>_staff.en_GB”...
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Error) MC:
> Installation of profile
> “org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>>>_staff.en_GB”
> failed with error: NSError:
> Desc : The profile “eduroam®” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be installed.
> US Desc: The profile “eduroam®” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be installed.
> Domain : MCProfileErrorDomain
> Code : 1009
> Type : MCFatalError
> Params : (
> "eduroam\U00ae"
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13000
> Type : MCFatalError
> Params : (
> eduroam
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13004
> Type : MCFatalError
> Params : (
> eduroam
> )
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Error) MC: Profile
> “org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org
> <mailto:org.1x-config.eduroam.nl.geant_staff.all_ AT geant.org>>>_staff.en_GB”
> failed to install with error: NSError:
> Desc : Profile Failed to Install
> Sugg : The profile “eduroam®” could not be installed.
> US Desc: Profile Failed to Install
> US Sugg: The profile “eduroam®” could not be installed.
> Domain : MCInstallationErrorDomain
> Code : 4001
> Type : MCFatalError
> ...Underlying error:
> NSError:
> Desc : The profile “eduroam®” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be installed.
> US Desc: The profile “eduroam®” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be installed.
> Domain : MCProfileErrorDomain
> Code : 1009
> Type : MCFatalError
> Params : (
> "eduroam\U00ae"
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13000
> Type : MCFatalError
> Params : (
> eduroam
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13004
> Type : MCFatalError
> Params : (
> eduroam
> )
> Aug 14 11:13:04 Apple-TV profiled[83] <Notice>: (Note ) MC: Removing
> certificate with persistent ID 636572740000000000000003
> Aug 14 11:13:04 Apple-TV airtunesd[47] <Notice>: 2023-08-14
> 11:13:04.966590 AM [AirPlay] Prefs changed
> Aug 14 11:13:04 Apple-TV profiled[83] <Error>: libMobileGestalt
> MGIOMFBSupport.c:219: IOMobileFramebufferGetMainDisplay failed:
> -536870212
> Aug 14 11:13:05 Apple-TV profiled[83] <Notice>: (Note ) MC: Loaded
> NetworkExtension.framework
> Aug 14 11:13:05 Apple-TV profiled[83] <Notice>: (Error) MC:
> Installation failed. Error: NSError:
> Desc : Profile Installation Failed
> Sugg : Profile Failed to Install
> US Desc: Profile Installation Failed
> US Sugg: Profile Failed to Install
> Domain : MCInstallationErrorDomain
> Code : 4001
> Type : MCFatalError
> ...Underlying error:
> NSError:
> Desc : Profile Failed to Install
> Sugg : The profile “eduroam®” could not be installed.
> US Desc: Profile Failed to Install
> US Sugg: The profile “eduroam®” could not be installed.
> Domain : MCInstallationErrorDomain
> Code : 4001
> Type : MCFatalError
> ...Underlying error:
> NSError:
> Desc : The profile “eduroam®” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be installed.
> US Desc: The profile “eduroam®” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be installed.
> Domain : MCProfileErrorDomain
> Code : 1009
> Type : MCFatalError
> Params : (
> "eduroam\U00ae"
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13000
> Type : MCFatalError
> Params : (
> eduroam
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13004
> Type : MCFatalError
> Params : (
> eduroam
> )
> Aug 14 11:13:05 Apple-TV mc_mobile_tunnel[97] <Notice>: (Error) MC:
> Install profile data error. Error: NSError:
> Desc : Profile Installation Failed
> Sugg : Profile Failed to Install
> US Desc: Profile Installation Failed
> US Sugg: Profile Failed to Install
> Domain : MCInstallationErrorDomain
> Code : 4001
> Type : MCFatalError
> ...Underlying error:
> NSError:
> Desc : Profile Failed to Install
> Sugg : The profile “eduroam®” could not be installed.
> US Desc: Profile Failed to Install
> US Sugg: The profile “eduroam®” could not be installed.
> Domain : MCInstallationErrorDomain
> Code : 4001
> Type : MCFatalError
> ...Underlying error:
> NSError:
> Desc : The profile “eduroam®” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be installed.
> US Desc: The profile “eduroam®” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be installed.
> Domain : MCProfileErrorDomain
> Code : 1009
> Type : MCFatalError
> Params : (
> "eduroam\U00ae"
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be installed.
> Sugg : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be installed.
> US Sugg: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13000
> Type : MCFatalError
> Params : (
> eduroam
> )
> ...Underlying error:
> NSError:
> Desc : The Wi-Fi network “eduroam” could not be configured for EAP.
> US Desc: The Wi-Fi network “eduroam” could not be configured for EAP.
> Domain : MCWiFiErrorDomain
> Code : 13004
> Type : MCFatalError
> Params : (
> eduroam
> )
>
>
>
>
>
>
>
>
> If someone has an idea...
>
>
>
>
> thanks :)
>
>
>
>
> Dick Visser
> To unsubscribe, send this message: mailto:sympa AT lists.geant.org
> <mailto:sympa AT lists.geant.org> <mailto:sympa AT lists.geant.org
> <mailto:sympa AT lists.geant.org>> <mailto:sympa AT lists.geant.org
> <mailto:sympa AT lists.geant.org> <mailto:sympa AT lists.geant.org
> <mailto:sympa AT lists.geant.org>>>?subject=unsubscribe%20cat-users
> Or use the following link:
> https://lists.geant.org/sympa/sigrequest/cat-users
> <https://lists.geant.org/sympa/sigrequest/cat-users>
> <https://lists.geant.org/sympa/sigrequest/cat-users>
> <https://lists.geant.org/sympa/sigrequest/cat-users;>
> <https://lists.geant.org/sympa/sigrequest/cat-users>
> <https://lists.geant.org/sympa/sigrequest/cat-users;>
> <https://lists.geant.org/sympa/sigrequest/cat-users;>
> <https://lists.geant.org/sympa/sigrequest/cat-users;>
>
>
>
>
>
>
> To unsubscribe, send this message: mailto:sympa AT lists.geant.org
> <mailto:sympa AT lists.geant.org> <mailto:sympa AT lists.geant.org
> <mailto:sympa AT lists.geant.org>>?subject=unsubscribe%20cat-users
> Or use the following link:
> https://lists.geant.org/sympa/sigrequest/cat-users
> <https://lists.geant.org/sympa/sigrequest/cat-users>
> <https://lists.geant.org/sympa/sigrequest/cat-users>
> <https://lists.geant.org/sympa/sigrequest/cat-users;>
>
>
>
> To unsubscribe, send this message: mailto:sympa AT lists.geant.org
> <mailto:sympa AT lists.geant.org>?subject=unsubscribe%20cat-users
> Or use the following link:
> https://lists.geant.org/sympa/sigrequest/cat-users
> <https://lists.geant.org/sympa/sigrequest/cat-users>


--
Tomasz Wolniewicz


To unsubscribe, send this message: mailto:sympa AT lists.geant.org
<mailto:sympa AT lists.geant.org>?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users
<https://lists.geant.org/sympa/sigrequest/cat-users>






Archive powered by MHonArc 2.6.24.

Top of Page