eduroam Development VC Minutes 2023-09-26 1530 CEST

Attendance

Attendees

Regrets

Agenda / Proceedings

  1. Welcome / Agenda Bashing

CP: if we were to ask Microsoft about what to do about RADIUS, what would be the reference implementation??
(reference for prior art from MSFT: https://learn.microsoft.com/en-us/azure/active-directory/architecture/multilateral-federation-introduction)

notes: Minimum: Have RADIUS/TLS (RadSec) (Preferably also RADIUS/TLS-PSK) be supported on AzureAD natively to use
do not require AADDS but have something that does RADIUS

Aspirational?:
items on the windows profiles that corrupt the profile itself and the client.

Paul: We’re investigating a login chicken/egg issue with online identities, while geteduroam EAP-TLS credentials are stored in a personal store, and after that Windows corrupts the profile but that’s the EAP side of things

Proposal from HPE Aruba - Connecting CloudAuth into eduroam
^^^
this sounds GeGC oriented and welcome any input and thoughts of course

CP:hot take: same as above – RadSec only? who is the operator on level 1/ emergency contact etc etc etc

side comment: would eduPKI still be the story in the AzureAD RADIUS TLS story too?

StefanW: Requirements on these outsourcers?

CP:maybe the RadSec (eduPKI?) cert is the verification/access required for said infra?
StefanW: available in cat 2.1.1 for NROs to be able to request eduPKI certs for themselves and for others/on behalf of others.

risk: Aruba/vendor then becomes (tacitly?) the arbitrator to get eduroam in a given region at times for cloud like solution?
Discussed and acknowledged on the risks and that the assignment of the eduPKI cert is likely a span of control that can mitigate this and have the devices/vendors be capable, but connectivity restricted to those who possess a valid eduPKI cert for RadSec connectivity.

  1. CAT 2.1.1 maintenance release

2a. geteduroam apps

3. EAP-FIDO update

EAP-FIDO is going to the IETF (Prague meeting, planned submission just in time for the I-D cutoff)

4. IETF update

not covered

5. Recurring OpenRoaming chitchat

not covered

6. AOB / next VC