Eduroam and setting identity privacy in Windows
j.potter at bathspa.ac.uk
Tue Feb 12 14:00:54 CET 2019
OK, this is great - I've had a look at the other options in Group policy
for setting up these connections, several of them look very promising.
Thanks again for everyone's advice, I'll let you know how I get on.
On Tue, 12 Feb 2019 at 11:04, Alan Buxey <alan.buxey at gmail.com> wrote:
> > Ok, certificates is an avenue I hadn't considered... I wasn't aware that
> > this was an option with eduroam (I'd just assumed we had to use PEAP).
> EAP-TLS, PEAP, EAP-TTLS, EAP-FAST, EAP-GTC, EAP-PWD etc all work over
> eduroam :)
> > Have you set something like this with eduroam in the past, or do you
> know if any
> > other universities have had this working?
> yes and yes - quite a few Universities in UK (and elsewhere) using
> EAP-TLS - and several moving
> to it. most are using commercial deployment tools (with user self
> service etc) - eg Cloudpath ES
> > So by setting the realm in the certificates, will the eduroam radius
> > servers forward the request correctly? I think I need to read up on this.
> yes, realm set in the cert - most clients can also define an outerID
> for the initial identifier
> List info/subscribe/unsubscribe? See
User Platform Engineer
Bath Spa University
T: 01225 876220
Join us on: Facebook <http://www.facebook.com/bath.spa.university>| Twitter
Newton Park, Bath, BA2 9BN
Think before you print
If you have received this message in error, please notify us and remove it
from your system. Any views or opinions expressed in personal emails are
solely those of the author and do not necessarily represent those of Bath
Spa University. Neither Bath Spa University nor the sender accepts any
responsibility for viruses and it is your responsibility to scan this email
and any attachments for viruses.
More information about the Freeradius-Users