Hi Per,
Thanks for this, I’ve tried your suggestion (having some issues, I’ll get there presently) – its good to know that someone else has it working though.
Jim Potter
Jisc
From: geteduroam-request AT lists.geant.org <geteduroam-request AT lists.geant.org>
On Behalf Of Per Mejdal Rasmussen
Sent: Thursday, August 31, 2023 12:32 PM
To: geteduroam AT lists.geant.org
Subject: Re: Configuring with multiple root CAs (for CA rollover)
Last year we (Aalborg University) replaced our CA, because it was singed with SHA1.
-
Generate new CA
-
Sign old CA with new CA as an intermediate CA.
-
Configure radius server to include old CA as an an intermediate CA.
-
Start using new CA on clients.
This procedure did not break any old clients, and did not require clients to support 2 CAs.
On 2023-08-31 10:34, James Potter wrote:
Hi all,
I’m looking to push out an eduroam profile that contains 2 root CAs. The current CA expires soon, I’d like as many users’ devices as possible to have a new CA in place so when we switch to a server cert (issued by the new CA) this change
has as little user impact as possible.
The issue I’m having is that deployment of the new profile appears erratic. For various Android versions, we see either one or 2 CAs being added (in the case of only 1 cert, I think only the newer one is deployed). I’ve not got a definitive
list of Android versions that work/don’t work.
Is deployment of multiple CAs meant to work? Has anyone else done this?
(Profile in question to test is University of Cumbria – staff/student profile has just the old CA; TESTING DO NOT USE has the new CA too)
Any help would be great,
Thanks,
Jim
Jisc
--
Per Mejdal Rasmussen
Senior Network administrator
Aalborg University, FRB1 B.1.87
Mobile: +45 2990 9887
Support: +45 9940 2020