Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

This page contains service description outlining how and where service should be used, targeted users, service delivery model and service elements and topology.

RESPONSIBLE: Information provided in this page is initially populated by the development team (during the transition phase), and revised based on the need or in a yearly service check by service_name Service Manager, with exception of CBA which remains the responsibility of business development teamperiodically.

Service description

The purpose of eduroam (education roaming) is to provide secure, worldwide roaming access service for the international research and education community.

...

eduroam (first-level) users are National Roaming Operators, that are responsible to operate eduroam service on a national level for their country. Up to date list of eduroam users is available at the eduroam monitor site.

Contacts

 

Service ManagerOwnerDevelopment Team LeadDeputy Service ManagerL1 supportL2 supportL3 support
 Miroslav Milinovic  Stefan Winter help@eduroam.org eduroam-ot@lists.geant.org eduroam-ot@lists.geant.org

...

The European eduroam service is built hierarchically. Confederation-level service is at the top level, and it provides the confederation infrastructure required to grant network access to all participating members of the eduroam service together with a set of supporting services. This confederation service is built upon the national roaming services, operated by the national roaming operators (NROs – in most cases, NRENs). National roaming services make use of other entities, for example, campuses and regional facilities. eduroam service delivery model is presented in the following picturepictures

...

Image Added






eduroam service delivery modelImage Modified



The European service is governed by the eduroam Steering Group (SG), while day-to-day operations are carried out by the eduroam Operations Team (OT).

In addition to operating the service’s basic technical infrastructure, the GÉANT eduroam team also delivers a supporting services suite to facilitate the widespread deployment of eduroam. This suite includes a central :

  • eduroam database (eduroam db) with information about participating institutions, https://monitor.eduroam.org/ 
  • monitoring & metering tools (f-ticks)

...

...

Service Elements

Technology infrastructure

...

Service main element

Description

Technologies used in delivery

Access URL

(two) European Top Level Radius servers - ETLREach server has a list of connected, federation top-level domains (.nl, .dk, .hr, .de etc.) serving the appropriate NRENs. The servers also maintain exception rules for domains whose federation membership is not immediately identifiable in the realm (typically gTLD realms such as ’.edu’, ‘.eu’, ‘.net’, etc.).
The servers accept requests for the federation domains they are responsible for, and subsequently forward them to the associated RADIUS server for that federation, and transport the response (i.e. result of the authentication request) back.

Protocols: RADIUS/UDP, RADIUS/TCP, RADIUS/DTLS and RADIUS/TLS

Software: Radiator

-

 


Supporting infrastructure

...

Technologies used in delivery

Service supporting element

Description

Access URL

Monitoring, Diagnostics and Metering tools in monitor.eduroam.org

The basic purpose of the eduroam monitoring, diagnostics and metering service is:  

  • to test the functionality of the FLRSs, TLRSs and the whole confederation infrastructure.
  • to collect information about the authentication traffic from the FLRSs that is used to provide usage statistics.

The eduroam monitoring and diagnostics element reports the results of the tests. An alert system is also implemented in order to inform OT and NRO responsible stuff about any malfunctions. The metering element relies on the F-Ticks tool.

Some of those info are public, while others are restricted to predefined user groups. The decision on the availability of the information lies with the eduroam Steering Group (SG).

https://monitor.eduroam.org/

https://monitor.eduroam.org/f_ticks_about.php

eduroam Database

eduroam database stores information about eduroam service such as:

  • NRO representatives and respective contacts.
  • eduroam

    NROs, SP and

    IdP official contacts.
  • Information about eduroam Service Providers (SP location, technical info).
  • Monitoring information.
  • Information about the usage of the service.
  • IdPs contacts, SP locations, monitoring, service usage. NROs are obliged to provide the information.

    There is a

    It is the obligation of the NROs to provide the above mentioned information.

    Information about the eduroam database design and data collection practice is available via the monitoring website, database section

    A web interface to the database is implemented, and it that allows various views of the database content. Some of these are public, while others are restricted to predefined user groups.The decision on the availability of the information lies with the eduroam SG.

    More info available at: monitoring website, database section

    https://monitor.eduroam.org/db_web/

    Trouble Ticketing System (TTS)

    First level support uses Trouble Ticketing System (TTS) to receive and process user requests. TTS system used is based on Request Tracker software and is provided by GEANT association. The support is available at help@eduroam.org  

    eduroam Websitewebsite

    This is the The eduroam website is the central information point for eduroam users at the same time providing information and links for all user groups. It is built by using WordPress CMS. The website is run and maintained by ?? . The content is edited by the PR team with support of the subject matter experts from OT.The eduroam wiki 

    https://www.eduroam.org/
    eduroam wikiIt provides technical information, guides and manuals targeting technical personnel in NRO, IdP and SP organisations that are responsible for deploying different parts of eduroam infrastructure. To smaller extent, the content is as well provides technical information targeting eduroam end-users. The wiki pages are run as part of GEANT projects wiki pages, that are maintained and run by GEANT Ltd. The content is provided as volunteer contribution by the eduroam community, and edited by the subject matter experts from the eduroam OT. The eduroam technical website is described in part Monitoring, Diagnostics and Meteringhttp://wiki.eduroam.org

    eduroam CAT

    The eduroam Configuration Assistant Tool (CAT) has been developed to help organisations offering their users eduroam access. The tool builds customised installers for a range of popular PC and smartphone platforms and enhances the security for the end user.
    The tool ensures that users are protected against rogue wi-fi hotspots accessing usernames and passwords.

    The tool builds a specific configuration for each participating organisation and so users should ensure they are downloading the correct installer.  eduroam CAT is available at eduroam cat web siteeduroam CAT e is hosted and run by SRCE (Croatia) as part of eduroam OT. eduroam CAT is an in-house development for GEANT project, developed and maintained by GN4-2 JRA3 activity as part of eduroam development activity. Source code is available at ?

    https://cat.eduroam.org/

    eduroam Managed IdP

    eduroam Managed IdP outsources the technical setup of eduroam IdP functions to the eduroam Operations Team. This leaves the institution only having to focus on its users and frees up valuable technical support resource.

    The system includes:

    • A web-based user management interface where end user credentials for access to eduroam can be created and revoked.
    • A technical infrastructure (“CA”) which issues and revokes credentials for users to access to eduroam.
    • A technical infrastructure (“RADIUS”) which verifies access credentials and subsequently grants access to eduroam.
    https://hosted.eduroam.org/ 

    Cost Benefit Analysis

    Provide URL to last valid CBA

    ...