Re: [87attendees] eduroam (Re: IETF wireless)

Chris Elliott <chelliot@pobox.com> Thu, 08 August 2013 11:27 UTC

Return-Path: <chelliot@gmail.com>
X-Original-To: 87attendees@ietfa.amsl.com
Delivered-To: 87attendees@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8C87F11E8103 for <87attendees@ietfa.amsl.com>; Thu, 8 Aug 2013 04:27:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.875
X-Spam-Level:
X-Spam-Status: No, score=-1.875 tagged_above=-999 required=5 tests=[AWL=0.102, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J8I4BIpbW6eD for <87attendees@ietfa.amsl.com>; Thu, 8 Aug 2013 04:27:43 -0700 (PDT)
Received: from mail-lb0-x229.google.com (mail-lb0-x229.google.com [IPv6:2a00:1450:4010:c04::229]) by ietfa.amsl.com (Postfix) with ESMTP id 2B4FE21E808E for <87attendees@ietf.org>; Thu, 8 Aug 2013 04:27:41 -0700 (PDT)
Received: by mail-lb0-f169.google.com with SMTP id u10so2343907lbi.14 for <87attendees@ietf.org>; Thu, 08 Aug 2013 04:27:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:reply-to:sender:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=12JuQmdjiMbHX4ulViU5ouPGAw5o6sN+RY1iYoC5hV0=; b=XXMzVy5fIEq0Owoh9XK3kpdvDZ3+nOSBxcnADP9zTL7UcsOeC0aMLAX8iHppzOxsAg 52IdVODyiHSjMNGhYA8DySYjCPsy5C8I8bU2iMCPAALHQ+welUfJ/KSR0iLaILObf5sy jF7uo9nak/GYskkpz8Z4OCXtTM1TUkIBOhuCDuw3Do4PLVT0dr2taiK5FvpqjYBaDzNf LgfihwT99zlxU6ZEz3TQR/R88wPFw5mzLwe4mIsq1yPuB+Nt/jNwhLh+mV7082CRomPh YXbaE36bofU0e82KhmMR+0oWD3r4Qg7h5xdH/TTd373oRxaq+UL4s/bQu3Gztw1uNZEY qJuw==
X-Received: by 10.152.45.5 with SMTP id i5mr3477299lam.32.1375961259894; Thu, 08 Aug 2013 04:27:39 -0700 (PDT)
MIME-Version: 1.0
Sender: chelliot@gmail.com
Received: by 10.114.3.44 with HTTP; Thu, 8 Aug 2013 04:27:19 -0700 (PDT)
In-Reply-To: <EMEW3|3e125feb730c9ef69244a1ba1af9fc6bp77BuM03tjc|ecs.soton.ac.uk|1D2EEB11-7226-44EB-8B59-A170B7067220@ecs.soton.ac.uk>
References: <767558DB-5546-4361-862E-0342F02AD435@ecs.soton.ac.uk> <EMEW3|a98bd69aea4959b1596d153ba8019962p74AmS03tjc|ecs.soton.ac.uk|767558DB-5546-4361-862E-0342F02AD435@ecs.soton.ac.uk> <alpine.OSX.2.01.1308050439080.146@173-11-110-132-sfba.hfc.comcastbusiness.net> <EB27A179-6515-43BE-B17B-2B853791788E@kumari.net> <alpine.DEB.2.02.1308080755220.5289@uplift.swm.pp.se> <52033C35.8060707@restena.lu> <E6B3BC8E-6BCB-4ECD-8E34-924CA6754507@tzi.org> <1D2EEB11-7226-44EB-8B59-A170B7067220@ecs.soton.ac.uk> <52036900.1@swin.edu.au> <EMEW3|3e125feb730c9ef69244a1ba1af9fc6bp77BuM03tjc|ecs.soton.ac.uk|1D2EEB11-7226-44EB-8B59-A170B7067220@ecs.soton.ac.uk>
From: Chris Elliott <chelliot@pobox.com>
Date: Thu, 08 Aug 2013 07:27:19 -0400
X-Google-Sender-Auth: iMh9Z-PROvUU2LmBBgLbDrQlKX0
Message-ID: <CAO_RpcJMo_c-PkB6ZZm9Opvnt7zbjYUapLJm_UZWNAFx-0SKkQ@mail.gmail.com>
To: Tim Chown <tjc@ecs.soton.ac.uk>
Content-Type: multipart/alternative; boundary="001a11c1b6961eec5c04e36df295"
Cc: "87attendees@ietf.org" <87attendees@ietf.org>, grenville armitage <garmitage@swin.edu.au>
Subject: Re: [87attendees] eduroam (Re: IETF wireless)
X-BeenThere: 87attendees@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: chelliot@pobox.com
List-Id: <87attendees.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/87attendees>, <mailto:87attendees-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/87attendees>
List-Post: <mailto:87attendees@ietf.org>
List-Help: <mailto:87attendees-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/87attendees>, <mailto:87attendees-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Aug 2013 11:27:43 -0000

All,

The eduroam ssid and associated authentication back end has been provided
at the IETF since IETF 78 in Maastricht. Paul Dekkers of SURFnet first
approached us with the idea of supporting this authentication system at
IETF meetings (thanks Geert Jan de Groot for bringing this to us!). Many of
the core network volunteer team offered suggestions and insights into how
to best support this. The eduroam folks that have most recently been
involved include Stefan Winter and Dubravko Penezic. Currently, Karen
O'Donoghue is our main contact with the eduroam folks as well as with
Radiator (our authentication server), Bjoern Zeeb handles the
authentication server side of things, and I maintain the AP and switch
configs.

Some of the interesting challenges we've encountered include authentication
timeouts as the eduroam Radius server "tree" is extensive and can result in
many Radius proxies before reaching the end (authoritative?) authentication
server. We're using a couple of techniques to improve reliability and
security and speed up authentication: Radius to the eduroam servers via
TLS/TCP, and supporting DNSRoam to shorten authentication times.

Thanks for the kind words. It's a pleasure to be able to help provide a
service that just works (most of the time!)

Chris.


On Thu, Aug 8, 2013 at 6:56 AM, Tim Chown <tjc@ecs.soton.ac.uk> wrote:

>
> On 8 Aug 2013, at 10:46, grenville armitage <garmitage@swin.edu.au> wrote:
>
> >
> >
> > On 08/08/2013 19:34, Carsten Bormann wrote:
> >> On Aug 8, 2013, at 08:35, Stefan Winter <stefan.winter@restena.lu>
> wrote:
> >>
> >>> The IETF also provides eduroam
> >>
> >> And tons of kudos go to whoever started this.
> >
> > +1
> >
> > (When I flipped open my laptop on the first day it automagically
> associated with eduroam. I initially thought this was some delayed holdover
> from when I'd last used WiFi at my home university. But lo and behold,
> eduroam in the IC was real, and worked well all week!)
>
> eduroam's been at the IETF a while.  Very welcome!
>
> Tim
> _______________________________________________
> 87attendees mailing list
> 87attendees@ietf.org
> https://www.ietf.org/mailman/listinfo/87attendees
>



-- 
Chris Elliott
chelliot@pobox.com