cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Tomasz Wolniewicz <address@concealed>
- To: Jan-Frederik Rieckers <address@concealed>, "address@concealed" <address@concealed>
- Subject: Re: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows)
- Date: Fri, 2 Oct 2026 09:37:59 +0200
- Authentication-results: mail.geant.org; dkim=pass (2048-bit key; unprotected) header.d=umk.pl address@concealed header.a=rsa-sha256 header.s=default header.b=kBwH4xfz; dkim-atps=neutral
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp.umk.pl 05B85200C9
It is semi-supported. If you click "Installer fine tuning and download" and you have TLS set in your profile then you will be able to set EAP-specific options for TLS. One of the is "Turn on EAP-TLS UserName". If you turn this on the Windows installer will ask the user to provide the username.
I realise that this is not exactly what you are looking for and I am not sure how this would work on other systems. Definitely CAT Linux installers would also ask, o Apple propably the system will ask as well.
However there is probably a much better solution. Create TLS certificates for users with CN=anonymous@realm and put the real username as the mail attribute in the certificate. You also need to setup your RADIUS server to act on email for user verification. With this it will univerally work across all platforms without any additional settings on client side. The CN is used as the RADIUS UserName.
Tomasz
W dniu 2.10.2026 o 08:56, Jan-Frederik Rieckers (via cat-users Mailing List) pisze:
Hi all,--
one of our institutions wants to use a specific "outer" ID for EAP-TLS.
(Technical background: The server root certificate expires and they want to migrate to a new root using a switch by outer ID)
They use their own certificates, but want to use CAT for configuring the devices. On Windows they noticed that the installer does not honor the outer ID configuration, apparently the Windows installer doesn't even include this.
From what I heard from the admin, windows needs a specific "DifferentUsername" property to not use the CN/UPN/... from the certificate.
Does the windows installer support it already and we're just holding it wrong?
If not: Is this something that the windows installer could be doing?
Cheers,
Janfred
Tomasz Wolniewicz
Attachment:
smime.p7s
Description: Kryptograficzna sygnatura S/MIME
-
[[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows),
Jan-Frederik Rieckers, 10/02/2026
-
Sv: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows),
Anders Nilsson, 10/02/2026
- Re: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows), Tomasz Wolniewicz, 10/02/2026
-
Re: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows),
Tomasz Wolniewicz, 10/02/2026
- Re: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows), Stefan Paetow, 10/02/2026
-
Sv: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows),
Anders Nilsson, 10/02/2026
Archive powered by MHonArc 2.6.19+.
