Subject: An open discussion list for topics related to the geteduroam service
List archive
- From: Paul Dekkers <paul.dekkers AT surf.nl>
- To: Gheorghiță Butnaru <gheorghita.butnaru AT staff.tuiasi.ro>
- Cc: geteduroam AT lists.geant.org
- Subject: Re: getting started with geteduroam
- Date: Mon, 1 Mar 2021 16:19:24 +0100
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=surf.nl; dmarc=pass action=none header.from=surf.nl; dkim=pass header.d=surf.nl; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ShdvbbIQ9/AsDWXPR7fO5Hf77UFi85p6lIbfU3xkV08=; b=ZpdKfj/CCRE6bktlqfFFIEVAF2IjGrRCr4VPC05K+/PffhhlUbFHUfAbcKcshsOm/ZapC8FUvvh8E6VyjXYP2sdjguMWgAS+iAzTyRyNi6Aq0lwcjriMoHiK4If0HYpCSUtg8QNTc+gtkqYLAHJbUSqlQEgPUAK7c71FxS8443rm+0zpKxz0JZRrWlK26lY2yjQ6aP16Rd3d50mEm9cqTEByN2tcw25jihfJCg3QApw7jcQwc94PZADM4C/k+rwi+o5ZJSWlto23yuu24OycGaJBDAVYI9Wm0ynaozOm5s3kKpGZKr7l3YB3vU177gLgX4liDDt95ae65IdL9wx0IQ==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RH/t6yud86mzE7dxcU/20O4/7zhMVqLSzHJqBSg3FCjgFnM2zESX6k+oPhKVhaw1VJ668g7nROWgtyih3ixCADYkEQPShLlioygGmsknXCbqbVUWlAiTBhKjt02yBZejcCV9ZjIpAMZ4+4drwQ/TPUPkMP9kYPj4hkM/opsR06j9w8QSEkFFyzpQw1ko+N8x+ydrkSQAd3ZAnDI87mSkhj/oq02ulSRkMppveVlIaUqt0FJxEcrM0CX7cwkN1p8ND+PkTKqzuWcUcSlB4ypnoAeWDPd4g3ZkwgFvY0sz0TkSNLqky3WQqnJrEqJ3j7UcwUp9Pi2Kym6EiFfQtzKJ0A==
- Authentication-results: surf.nl; dkim=none (message not signed) header.d=none;surf.nl; dmarc=none action=none header.from=surf.nl;
Hi,
CAK0iHg8b53vbb5Y+irHF-saVG_4VDz_gMVWfaw8+oZRYw-12FA AT mail.gmail.com">Thanks for your fast response.
On Mon, Mar 1, 2021 at 4:15 PM Paul Dekkers <paul.dekkers AT surf.nl> wrote:
We bring all eduroam CAT profiles into the list of institutions and profiles. If you're not listed, drop me a note. It's most likely stale cache (and our caching is a bit too aggressive now ;-) we need to work on that).These are both the profiles that you use with your regular RADIUS accounts, as well as profiles that may use a specific "geteduroam-only" approach:
CAK0iHg8b53vbb5Y+irHF-saVG_4VDz_gMVWfaw8+oZRYw-12FA AT mail.gmail.com">So my previous answer is more or less in case you want to use "normal" CAT profiles.
If you want to create eduroam pseudo-accounts based on your federated eduGAIN SAML-authentication, that's indeed also part of geteduroam. You can use this as a service from GEANT, if your NRO agrees. (You'd get eg. tuiasi-ro.get.eduroam.org as a realm.)
You also need to create a profile for this in CAT, so you can be discovered from both CAT and geteduroam. (CAT will however redirect you from the website. It works quite well actually.)
I more or less like their blessing (also because they need to assist you potentially in eduGAIN if you were not in there) they don't need to do anything. It's a bit like hosted IdP and CAT services, they're also not used without NRO consent ;-) But also, in the future they may need to indicate/help onboarding of institutions, like they do with CAT.
For onboarding we need to know the eduGAIN entityID of the IdP,
basically.
CAK0iHg8b53vbb5Y+irHF-saVG_4VDz_gMVWfaw8+oZRYw-12FA AT mail.gmail.com">No, you can create a second profile if you wish. We have some that create two profiles like "E-mail and password" and "geteduroam", or label the geteduroam one "experimental".If we are going to do these, it means that we will be geteduroam-only?
CAK0iHg8b53vbb5Y+irHF-saVG_4VDz_gMVWfaw8+oZRYw-12FA AT mail.gmail.com">One thing you need to take into account is if you make additional authorization decisions, like VLAN assignments.From what I know, right now, GEANT talks in every documentation for eduroam about CAT and not about geteduroam. Wouldn't that be puzzling for users?Also, what changes do we need to make to our infrastructure? And at what level (radius, wireless access controllers)?
CAK0iHg8b53vbb5Y+irHF-saVG_4VDz_gMVWfaw8+oZRYw-12FA AT mail.gmail.com">
If you want to host your own pseudo-accounts, that's definitely possible! There is documentation.
However, this server part is the part of the concept that is still a bit "in flux". We're likely to make changes that will require database migrations and what not. Of course we implement this ourselves in the centralized infrastructure, so that will continue to work well. We may not be able to offer a lot of support on this if you host it yourself (considered "for the experts") but it is documented, with a reference implementation for Debian. And if you follow the commits and notes and have a test-implementation, you're problably fine.
One advantage may be that authentication stays on campus?
For the pseudo-account server code, you'd be looking at
https://github.com/geteduroam/letswifi-ca
CAK0iHg8b53vbb5Y+irHF-saVG_4VDz_gMVWfaw8+oZRYw-12FA AT mail.gmail.com">In all this puzzle, where do the client certificates fit? Right now, we are using EAP-PEAP and EAP-TTLS for our eduroam infrastructure. I am interested in the EAP-TLS if it's not too complex to implement and does not become harder for our users.
The apps will create EAP-TLS profiles on your devices, after the SAML federated login. The users won't really notice it's not PEAP or TTLS I guess. There's no credential to steal though.
Profiles are typically valid for a year. The iOS app and future
Android apps will warn you 5 days before expiration - but the
current Android doesn't do that.
There is a Windows client, and for macOS we create .mobileconfig
profiles pending a macOS client. I heard the Windows client
doesn't always detect network adapters for some; you need to
check. There is no solution yet for Chromebooks, and nothing for
Linux - but that's not because Linux isn't possible, it just needs
some love from a developer.
Regards,
Paul
CAK0iHg8b53vbb5Y+irHF-saVG_4VDz_gMVWfaw8+oZRYw-12FA AT mail.gmail.com">Sorry if my questions sound dumb. I could not found more documentation besides https://www.geteduroam.app/.
Also, if it's worth mentioning, we have around 18k users.
Thanks,
Gheorghita BUTNARU,
Gheorghe Asachi Technical University of Iaşi
- getting started with geteduroam, Gheorghiță Butnaru, 03/01/2021
- Re: getting started with geteduroam, Paul Dekkers, 03/01/2021
- Re: getting started with geteduroam, Gheorghiță Butnaru, 03/01/2021
- Re: getting started with geteduroam, Paul Dekkers, 03/01/2021
- Re: getting started with geteduroam, Gheorghiță Butnaru, 03/03/2021
- Re: getting started with geteduroam, Jørn Åne de Jong, 03/10/2021
- Re: getting started with geteduroam, Gheorghiță Butnaru, 03/10/2021
- Re: getting started with geteduroam, Paul Dekkers, 03/01/2021
- Re: getting started with geteduroam, Gheorghiță Butnaru, 03/01/2021
- Re: getting started with geteduroam, Ralf Paffrath, 03/04/2021
- Re: getting started with geteduroam, Paul Dekkers, 03/01/2021
Archive powered by MHonArc 2.6.19.