Taskforce Mobility Mailarchive
| Subject | Effects of Incorrect EAP Termination in eduroam |
| From | Jan Tomasek <jan.tomasek@xxxxxxxxx> |
| Date | Wed, 18 Jun 2008 16:58:34 +0200 |
Hi,few months ago I discovered a very interesting effect of incorrect EAP termination in eduroam. Incorrectly configured FreeRADIUS 1.x.x server (but not only FreeRADIUS) might be used as proxy for hiding true identity of an user. Because this mistaken configuration is part of "eduroam cookbok" the number of misconfigured servers might be quite high. But, I First published this problem in February in GN2-SA5, so I hope that most of misconfigured servers are fixed now.
Detailed description of the problem and its solution: http://www.cesnet.cz/doc/techzpravy/2008/incorrect-eap-termination-in-eduroam/I suggest to all NREN level admins to check all their realms. Tools are part of my report above.
Have fun ;) -- -------------------------------------------------------------- Jan Tomasek aka Semik work: CESNET, z.s.p.o. http://staff.cesnet.cz/~semik Zikova 4, 160 00 Praha 6 phone: +420 234 680 279 Czech Republic phone: +420 312 661 010 http://www.cesnet.cz/
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
- Prev by Date: [Fwd: I-D Action:draft-ietf-radext-radsec-00.txt]
- Next by Date: Draft agenda - Meeting July 8
- Previous by thread: [Fwd: I-D Action:draft-ietf-radext-radsec-00.txt]
- Next by thread: Draft agenda - Meeting July 8
- Index(es):