eduroam Development VC Minutes 2026-07-14
Attendance
Attendees
- Stefan Winter (RESTENA)
- Anders Nilsson (Non Polar Bear) (SUNET)
- Stefan Paetow (Jisc)
- Ed Kingscote (CANARIE)
- Paul Dekkers (SURF)
- Chris Rohrer (Switch)
- Frederic Gerber (Switch)
- Fabian Mauchle (Switch)
- Mohit Sharma (CANARIE)
- Tomasz Wolniewicz (PCSS)
- Maja Górecka-Wolniewicz (PCSS)
- Guy Halse (TENET)
- Mary Bull (Internet2)
- Louis Twomey (Asiera)
- Martin Stanislav (SANET)
- Janfred Rieckers (DFN)
- Alan DeKok (InkBridge)
Regrets
- Zenon Mousmoulas (GRNET)
Agenda / Proceedings
Welcome / Agenda Bashing
CAT / Managed SP
- new version deployment ongoing, slight delay
- aiming for beginning of August
- local copy of Android geteduroam app - switch to F-Droid listing?
- Seems reasonable to link to their listing https://f-droid.org/en/packages/app.eduroam.geteduroam/
geteduroam
- macOS version now in the App store!
- This version (still) produces a packaged mobileconfig.
- Nicer UI, and can remind you of cert expiry
- best to remove mobileconfig (or manual configurations) first
- root CA for “Hosted Accounts” (p.k.a. pseudocredentials)
- Windows cert store has only few CAs “built-in” on shipment; most are loaded dynamically on-use
- but does not consider EAP uses, so only few roots deterministically available
- short list of CAs to choose from for max compatibility
- an option is to “give up” and use a private CA instead (with all the issues about “trust-everything” on the Windows platform)
- on Windows, install not the CA but trust-certificate-by-fingerprint (avoids the scary CA install pop-up)
- trust-by-fingerprint is less of an issue than usual - Hosted Account profiles get re-installed on a regular basis anyway, due to client cert expiry
- This is notably only about the “pseudo-credentials” profiles issued by geteduroam portal; and on the portal, it is configurable whether
- a private CA (fingerprint trust),
- private CA (CA trust ), or
- public CA (CA trust) is to be used.
- The discussion revealed that the question of “security popup during installation & ability to abuse a private root CA” is not universally considered a big problem. For some it is (and worth working on a solution as above), for some it is not (and then simply installing the CA and trusting it is fine)
- macOS version now in the App store!
3a. IdP server cert CA rollover:
- this is happening more often than one likes, and sometimes even on short notice
- IETF
- for people doing accounting, Acct-Status-Type = Periodic-Update proposal
- meeting next week in Vienna
- WFA / WBA
- RADIUS Interop group (old “conformance”) is making little progress
- Google Android + NPS incompatibility issue
- Google considers adding PEAP (for Passpoint) as a feature because they say the Passpoint spec only refers to the 5 methods as required.
- Event Announcements / Wrap-ups
- There is an open-source option for BYOD EAP-TLS. Join a call on August 14 at 10:30am - 11:15am ET to hear about geteduroam and the Let’s Wifi portal Adam Ferraro (Temple University), Neil Hollands (University of Iowa), Bryanna Marihugh (Manhattan Area Technical College), and Paul Dekkers (SURF) discuss their implementation and discovery work with this tool. Introduced by Rob Gorrell (UNC-Greensboro). The recording will be available on the eduroam wiki. Put it on your calendar
AOB
- radsecproxy 1.11.3 released (bug fixes) https://github.com/radsecproxy/radsecproxy/releases/tag/1.11.3
- interesting case reported here https://github.com/GEANT/CAT/issues/385
Next call 11 Aug 2026, 1530 CEST