Subject: An open discussion list for topics related to the geteduroam service
List archive
- From: James Potter <Jim.Potter AT jisc.ac.uk>
- To: Paul Dekkers <paul.dekkers AT surf.nl>
- Cc: "geteduroam AT lists.geant.org" <geteduroam AT lists.geant.org>
- Subject: RE: eap-config format supported by geteduroam
- Date: Thu, 20 Jun 2024 08:29:58 +0000
- Accept-language: en-GB, en-US
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=DMU2iX8UY11cYEsDuDP/FxuZtPhnT1KacOz28BtOO2U=; b=hS/KBTjE6Ze6GmfBN+6In0Dso+JB3nzRhbEw5/9D3WhB1xmyOn7CIUzuX+sPKra1OFpQUCXyNC7n5qeliLjnNeO3j6D9WWLmID8viAKwQmRDqEtQiGg3jaFUVQ3KMPmuMfiA+VBxs3FZKNBPqo9MtXs1d3YHoP1Go1QdslK01uyatycbyEeRQpOb9yYNVYwTDeAoMSalsnShNAPdGx20As2vMxvUvKiL+Vfmk39aE4m3C4prp6p0ID19moPV33F8tLS4Cexr0KMbEoNU949Zy7j6wn9/WH3ZmR5yqADsbfLaBAVX6hK6DGi7xvGqo0zpKA+LnF9XnfOQpwXWi2QwBQ==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=n+lF9evmlP5gPdSY25aWtT+cmQ7+RKwQI6ts+HITvNfND0YAkxGtNhHYOOjDpgoArW5JaJ2KBefBIWwti02njHuksDvrL7pCstb5jcrrbOeaGUyzi4EEQBtLsjy3EOwp+7j3MoM9zYJQE1S2KG0piCa79uFhSh2/Wz0w2g/EEVa4GeZF4oNlPUQ8/129UAMkw356mY0dZLluscmUm1i0eC9zjos9d5/r3sdIuCoUBA3Q9j1n4Jkeq47dn9+wAO+EQK7z14EBtAl6pqYUorOAs7N+yARa2OMbelOxCXvxbQNipb30lMZbhpruCRg12BeRmiJyOQPEJPmv7RtCAV1+5w==
- Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=jisc.ac.uk;
- Msip_labels: MSIP_Label_23fbfc4d-4f2b-405b-9635-512bd5247bcf_ActionId=ede1e058-85cb-484c-869d-e3a7607e649d;MSIP_Label_23fbfc4d-4f2b-405b-9635-512bd5247bcf_ContentBits=0;MSIP_Label_23fbfc4d-4f2b-405b-9635-512bd5247bcf_Enabled=true;MSIP_Label_23fbfc4d-4f2b-405b-9635-512bd5247bcf_Method=Privileged;MSIP_Label_23fbfc4d-4f2b-405b-9635-512bd5247bcf_Name=Confidential - External;MSIP_Label_23fbfc4d-4f2b-405b-9635-512bd5247bcf_SetDate=2024-06-20T08:29:57Z;MSIP_Label_23fbfc4d-4f2b-405b-9635-512bd5247bcf_SiteId=48f9394d-8a14-4d27-82a6-f35f12361205;
Hi Paul,
Thanks for quick answers!
OK – I’ll give that a go from the xsd file. And base64 PKCS12, spot on.
I’d found the LetsWifi portal after I’d written a chunk of my service… I’ve not used OAuth, I used SAML (we do shibboleth support, I’ve stuck to what I know here), not sure how well that will integrate with geteduroam, we’ll find out. It works nicely on windows…
I’ve built my service to be multi tenant, HSM backed + have an OCSP responder, happy to do a show + tell if you’re interested.
Thanks,
Jim Jisc
From: Paul
Dekkers <paul.dekkers AT surf.nl>
Hi, On 20/06/2024 10:07, James Potter (via geteduroam Mailing List) wrote:
So basically you recreated the geteduroam portal? ;-) (I hope you knew about its existence!) (That's fine, no judgement, but I hope you also do it via OAUTH to mimic the geteduroam native workflow and have it most secure, and then there's an alternative for admins to choose software and it would make sense and integrate well with the Apps and authentication.)
I think a better and more current source is in the CAT repo: https://github.com/GEANT/CAT/blob/master/devices/eap_config/eap-metadata.xsd
I think it's easier to test with the .eap-configs that the letswifi-portal produces, or the output from CAT itself. Looking at what letswifi-portal produces, it looks like: <ClientSideCredential> Hope this helps, Regards,
|
- eap-config format supported by geteduroam, James Potter, 06/20/2024
- Re: eap-config format supported by geteduroam, Paul Dekkers, 06/20/2024
- RE: eap-config format supported by geteduroam, James Potter, 06/20/2024
- Re: eap-config format supported by geteduroam, Paul Dekkers, 06/20/2024
- RE: eap-config format supported by geteduroam, James Potter, 06/20/2024
- Re: eap-config format supported by geteduroam, Stefan Paetow, 06/20/2024
- Re: eap-config format supported by geteduroam, Jørn Åne de Jong, 06/23/2024
- Re: eap-config format supported by geteduroam, Stefan Paetow, 06/20/2024
- RE: eap-config format supported by geteduroam, James Potter, 06/20/2024
- Re: eap-config format supported by geteduroam, Paul Dekkers, 06/20/2024
Archive powered by MHonArc 2.6.24.