eduroam Development VC Minutes 2026-05-05
Attendance
Attendees
- Stefan Winter (RESTENA)
- Stefan Paetow (Jisc)
- Janfred Rieckers (DFN)
- Mohit Sharma (CANARIE)
- Fabian Mauchle (Switch)
- Derek Eiler (NSHE)
- Paul Dekkers (SURF)
- Mary Bull (Internet2)
- Ed Kingscote (CANARIE)
- Louis Twomey (Asiera)
- Donald Coetzee (TENET)
- Zbigniew Ołtuszyk (PSNC)
- Guy Halse (TENET)
- Frederic Gerber (Switch)
- Ed Wincott (Jisc)
- Zenon Mousmoulas (GRNET, late)
Regrets
Agenda / Proceedings
Welcome / Agenda Bashing
CAT / Managed SP
- Fabian tested the pre-release version on cat-test.eduroam.org
- no IPv6 issues there
- TLS-PSK and TLS-certificates also worked fine
- improvements suggested for implementations like Ubiquiti (subjectAltName:DNS etc.)
- note that shared secret for RadSec is “radsec”
- side note: RadSec at all vendors is not very pedantic re certificate properties - they only check chain validation; no cert OID, subjectAltName, etc.
- Guy also tested API accesses - some restrictions re IdP vs. SP permissions not enforced yet. Dev team is aware.
- Fabian tested the pre-release version on cat-test.eduroam.org
geteduroam
- do you have reference customers using geteduroam with EAP-TLS? Recommendations?
- This refers to IdPs who have their own PKI and would set up eduroam using the geteduroam apps.
- geteduroam apps would “merely” need to find the client certificate on the OS and associate it to eduroam settings as set in CAT
- But not sure if and on which OSes this works; too little demand for this deployment model so far.
- Best to try what happens and report about findings.
- The easier/more proven path would probably be to run the geteduroam portal locally and use its generated certificates. That way, cert comes bundled with the installer.
- There is a perception that deploying the portal is difficult - and some IdP admins tend towards commercial solutions because of that.
- Dev team is open for feedback and suggestions on how to make this easier.
- Side issue: the term “pseudo-account” is maybe not the best. Service-specific credential? Derived Credential? “personal eduroam profile”?
IETF
- new radsec document out; now with IESG
WFA / WBA
- Some movement in the WFA to make Radsec mandatory for things
- WBA is in the process of developing test suites for relevant aspects
AOB
- CANARIE Webinar - Certificates in eduroam.
- RADIUS Conference 2026 @TNC26 (Mon 08 June, 1400) + virtual talks on 15 June. .
- Jisc’s eduroam Fundamentals webinar on 2 June (1pm UTC) - more details TBA
- Radiator 10 for eduroam?
- Paul checked; it’s entirely different product, not a drop-in replacement
- feature sets differ between 4 and 10, needs case-by-case evaluation
- RADIUS flows: NROs see packet decode error, particularly in high-load situations from ETLR. Currently under investigation in DE.
Next call 19 May 2026 1530 CEST