Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows)

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Re: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows)


Chronological Thread  
  • From: Stefan Paetow <address@concealed>
  • To: "address@concealed" <address@concealed>
  • Subject: Re: [[cat-users]] Anonymous Outer ID with EAP-TLS (specifically: Windows)
  • Date: Fri, 2 Oct 2026 09:12:53 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=nebvWdqcbfBWXPGGTpN4Sbf2gUSBnT6t+3S1Vr8K0ig=; b=TEOG5xhgdbUvvSFMSsX445HUczsrQ94nPnIrtQL7oYOzOJgbcBuvzNx0RWGEtRRKQg7VPqSi4lAx5AtdYobiOJHeVpzx6Rh1DLv0YLlZjemFMjlFxCbz6ni9SUdoUBDSAsrxiIUEwYwE3DghGBuz5Kkz4kt5pGDV+NTPmuQEhI5GcImu4slwRWdq+k4Y+OyrJ07Si3KtiTSSHiDqG09hZdAw/jmDUJi6LfAj3ERr/yRfTBpxBKyu7lbmkwsiJV+5IK4zd3JlRFYA/7f+5lET+5PWVb/CyyZKoHXAnzdvVny0hI3hDTA0Sae/4AZpokbTMfy2b3qHgmhhbzorQoq7mg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=HtLsMZ8zxJmb9ue7wZp5uKpC3GHbnvYjNFRx3HEdmMeQd+qsDUXwjxpCrzHXBfZCHbN8px7PGdVUtVC5HVTnBuZvFnpeNuqKGLQrccDxl+TNmXzHphTEyRaDM/tDksTxw2t7gAOW2neVbf5vhDY6SujU8qND2SCoCO0759je1yAqkQMurYGujOsODMEp6OQlaiuw64nO7H1hsOsLKlZhLDe5IokzbjV83IL22PqtuaI27gRFwmlvz5Myf4u99L8D+4TOzcyAuiywM2GT9mVk09uHN0ravESg0+RC+ePU/TXd8dUsialdN2dGm0dQPCVBNKcHWriSAPhZCqaLsBatpQ==
  • Authentication-results: mail.geant.org; dkim=pass (2048-bit key; unprotected) header.d=jisc.ac.uk address@concealed header.a=rsa-sha256 header.s=selector2 header.b=B6jFGAzX; dkim-atps=neutral
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=jisc.ac.uk;
  • Msip_labels: MSIP_Label_190374fc-c2b5-4c8e-bee8-6305ebc1550a_Enabled=True;MSIP_Label_190374fc-c2b5-4c8e-bee8-6305ebc1550a_SiteId=48f9394d-8a14-4d27-82a6-f35f12361205;MSIP_Label_190374fc-c2b5-4c8e-bee8-6305ebc1550a_SetDate=2026-10-02T09:12:23.5899379Z;MSIP_Label_190374fc-c2b5-4c8e-bee8-6305ebc1550a_Name=Private - External;MSIP_Label_190374fc-c2b5-4c8e-bee8-6305ebc1550a_ContentBits=0;MSIP_Label_190374fc-c2b5-4c8e-bee8-6305ebc1550a_Method=Privileged

What Tomasz suggests. 

Park the real username (or maybe an encoded form of it) in one of the sAN records (mail, dNS, URI...) and leave the CN= as 'anonymous@...' or whatever the specific username is that they want to use.  :-)

Kind regards

Stefan Paetow
Federated Roaming Technical Specialist
eduroam(UK), Jisc – 20 years of free Wi-Fi for the UK R&E sector

email/teams: address@concealed
gpg: 0x3FCE5142

For eduroam support, please contact the eduroam team via address@concealed and mark it for eduroam’s attention.
I am not available on Mondays and Fridays between 12:00 and 15:00 London time (UTC in winter, UTC+0100 in summer).

Note: I don’t expect a reply outside of your working hours, since I work internationally with colleagues in different nationalities with different religions, customs, and holidays. Reply when it is convenient for you.

Jisc is a registered charity (in England and Wales under charity number 1149740; in Scotland under charity number SC053607) and a company limited by guarantee registered in England under company number 05747339, VAT number GB 197 0632 86. Jisc's registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.

Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.

For more details on how Jisc handles your data see our privacy notice here: https://www.jisc.ac.uk/website/privacy-notice


On 02/10/2026, 08:38, "address@concealed" <address@concealed> wrote:

It is semi-supported. If you click "Installer fine tuning and download"
and you have TLS set in your profile then you will be able to set
EAP-specific options for TLS. One of the is "Turn on EAP-TLS UserName".
If you turn this on the Windows installer will ask the user to provide
the username.

I realise that this is not exactly what you are looking for and I am not
sure how this would work on other systems. Definitely CAT Linux
installers would also ask, o Apple propably the system will ask as well.

However there is probably a much better solution. Create TLS
certificates for users with CN=anonymous@realm  and put the real
username as the mail attribute in the certificate. You also need to
setup your RADIUS server to act on email for user verification. With
this it will univerally work across all platforms without any additional
settings on client side. The CN is used as the RADIUS UserName.

Tomasz


W dniu 2.10.2026 o 08:56, Jan-Frederik Rieckers (via cat-users Mailing
List) pisze:
> Hi all,
>
> one of our institutions wants to use a specific "outer" ID for EAP-TLS.
> (Technical background: The server root certificate expires and they
> want to migrate to a new root using a switch by outer ID)
>
> They use their own certificates, but want to use CAT for configuring
> the devices. On Windows they noticed that the installer does not honor
> the outer ID configuration, apparently the Windows installer doesn't
> even include this.
>
> From what I heard from the admin, windows needs a specific
> "DifferentUsername" property to not use the CN/UPN/... from the
> certificate.
>
> Does the windows installer support it already and we're just holding
> it wrong?
> If not: Is this something that the windows installer could be doing?
>
> Cheers,
> Janfred
>
--
Tomasz Wolniewicz





Archive powered by MHonArc 2.6.19+.

Top of Page