Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

eduroam RADIUS server logs


GEANT central opsNROIdPSP
Dataset description:Logs from the European top level RADIUS servers (ETLR)Logs from the national top level RADIUS server(s) (FTLR)Logs from the IdP RADIUS server(s)Logs from the SP RADIUS server(s)
Purpose of processing:

Troubleshooting issues and resolving security incidents.

Troubleshooting issues and resolving security incidents.

Recommendation by the eduroam Service Definition.

Troubleshooting issues and resolving security incidents.

Requirement by the eduroam Service Definition.

Troubleshooting issues and resolving security incidents.

Recommendation by the eduroam Service Definition.

Requirement by the eduroam Service Definition is to keep the logs of public IP addresses assigned to users and its relation to users MAC address.

Data source:

Data is logged in the ETLR servers when a RADIUS authentication or response passes (user accesses eduroam in another country)

Data is logged in the FTLR server(s) when a RADIUS authentication or response passes (user accesses eduroam in another institution)

Data is logged in the IdP RADIUS server(s) when a RADIUS authentication or response passes (institution user accesses eduroam anywhere)Data is logged in the SPs RADIUS server(s) when a RADIUS authentication or response passes. (user accesses eduroam at that SPs location)
Data storage and access:

Data is stored in the ETLR servers, accessible only to the eduroam operational team personnel.

Data is stored in the FTLR server(s), accessible only to the NRO operational team personnel.

(This may vary based on local practices)

Data is stored in the IdP server(s), accessible only to the IdP operational team personnel.

(This may vary based on local practices)

Data is stored in the SP server(s), accessible only to the IdP operational team personnel.

(This may vary based on local practices)

Data transfer:

No

NoNoNo
Data retention:?

Depends on the local policy.

eduroam Service Definition recommendation is: The minimum log retention time is six months, unless national regulations require otherwise

Depends on the local policy.

eduroam Service Definition recommendation is: The minimum log retention time is six months, unless national regulations require otherwise.

Depends on local the policy.

eduroam Service Definition recommendation is: The minimum log retention time is six months, unless national regulations require otherwise.

Personal data processed:YesYesYesYes


Dataset content


Data itemIs personal data?
central opsNROIdPSP
1Timestamp -   The time the authentication request was exchanged i.e usert tried to access the eduroam service
  •   
  •   
  •   
  •   
2

Outer EAP-identity - username@institution_domain, username can be anonymised but not all users do that

  •   
  •   
  •   
  •   
3Inner EAP-identity - username@institution_domain
  •   
  •   
  •   
  •   
4Calling-Station-Id - users MAC address
  •   
  •   
  •   
  •   
5Authentication result
  •   
  •   
  •   
  •   
6Chargeable-User-Identity - users anonymous ID
  •   
  •   
  •   
  •   
7IP address assigned by the SP after the sucessfull authenticaiton, including its relation to users MAC address
  •  ?
  •   
  •   
  •   

...


Data itemIs personal data?Comment
1REALM - As in users EPPN used for the authentication (for example “@education.lu”) - contains the user’s country of origin and the institution of originYes
2Calling-Station-Id - User’s device MAC addressYes
3Viscountry - ISO country code of the NRO that generated the log messageYesNo (VP proposal)
4Visinst - Identifier of visited institution i.e. operator-name RADIUS attributeYesNo (VP proposal)
5Result - Authentication outcome: OK / FAILNo

...