Taskforce Mobility Mailarchive


Subject Re: WPA problem and eduroam
From Tomasz Wolniewicz <twoln@xxxxxx>
Date Wed, 03 Dec 2008 12:13:06 +0100

Miroslav Milinovic pisze:
> Let me clarify myself on the Policy point.
>
> Policy says: "an encryption level SHOULD be WPA/TKIP or better". So
> Policy is not a show stopper for providing WPA/AES only.
>
Yes it does, but no university can run AES only without kicking off a
significant number of users. And if we want to be guest-friendly then we
should not disable TKIP on our eduroam SSID at least for quite some time.
The fact that the policy allows us to run: dynamic WEP, WPA/TKIP,
WPA2/AES is exactly the problem. With a single SSID we have no option
but allow that, but this network will never work according to the
scenario "start your device and be on-line". eduroam2 can bring us a lot
closer to this, and what is more important, opens a path for achieving this.

Tomasz

-- 
Tomasz Wolniewicz    
          twoln@xxxxxx        http://www.home.umk.pl/~twoln

Uczelniane Centrum Informatyczne   Information&Communication Technology Centre
Uniwersytet Mikolaja Kopernika     Nicolaus Copernicus University,
pl. Rapackiego 1, Torun               pl. Rapackiego 1, Torun, Poland
tel: +48-56-611-2750     fax: +48-56-622-1850       tel kom.: +48-693-032-576