eduroam Development VC Minutes 2026-05-05

Attendance

Attendees

  • Stefan Winter (RESTENA)
  • Stefan Paetow (Jisc)
  • Janfred Rieckers (DFN)
  • Mohit Sharma (CANARIE)
  • Fabian Mauchle (Switch)
  • Derek Eiler (NSHE)
  • Paul Dekkers (SURF)
  • Mary Bull (Internet2)
  • Ed Kingscote (CANARIE)
  • Louis Twomey (Asiera)
  • Donald Coetzee (TENET)
  • Zbigniew Ołtuszyk (PSNC)
  • Guy Halse (TENET)
  • Frederic Gerber (Switch)
  • Ed Wincott (Jisc)
  • Zenon Mousmoulas (GRNET, late)

Regrets

Agenda / Proceedings

  1. Welcome / Agenda Bashing

  2. CAT / Managed SP

    • Fabian tested the pre-release version on cat-test.eduroam.org
      • no IPv6 issues there
      • TLS-PSK and TLS-certificates also worked fine
      • improvements suggested for implementations like Ubiquiti (subjectAltName:DNS etc.)
      • note that shared secret for RadSec is “radsec”
    • side note: RadSec at all vendors is not very pedantic re certificate properties - they only check chain validation; no cert OID, subjectAltName, etc.
    • Guy also tested API accesses - some restrictions re IdP vs. SP permissions not enforced yet. Dev team is aware.
  3. geteduroam

    • do you have reference customers using geteduroam with EAP-TLS? Recommendations?
    • This refers to IdPs who have their own PKI and would set up eduroam using the geteduroam apps.
    • geteduroam apps would “merely” need to find the client certificate on the OS and associate it to eduroam settings as set in CAT
    • But not sure if and on which OSes this works; too little demand for this deployment model so far.
    • Best to try what happens and report about findings.
    • The easier/more proven path would probably be to run the geteduroam portal locally and use its generated certificates. That way, cert comes bundled with the installer.
    • There is a perception that deploying the portal is difficult - and some IdP admins tend towards commercial solutions because of that.
    • Dev team is open for feedback and suggestions on how to make this easier.
    • Side issue: the term “pseudo-account” is maybe not the best. Service-specific credential? Derived Credential? “personal eduroam profile”?
  4. IETF

    • new radsec document out; now with IESG
  5. WFA / WBA

    • Some movement in the WFA to make Radsec mandatory for things
    • WBA is in the process of developing test suites for relevant aspects
  6. AOB

    • CANARIE Webinar - Certificates in eduroam.
    • RADIUS Conference 2026 @TNC26 (Mon 08 June, 1400) + virtual talks on 15 June. .
    • Jisc’s eduroam Fundamentals webinar on 2 June (1pm UTC) - more details TBA
    • Radiator 10 for eduroam?
      • Paul checked; it’s entirely different product, not a drop-in replacement
      • feature sets differ between 4 and 10, needs case-by-case evaluation
    • RADIUS flows: NROs see packet decode error, particularly in high-load situations from ETLR. Currently under investigation in DE.
  7. Next call 19 May 2026 1530 CEST

  • No labels