eduroam technical information
On this page you will find technical details on eduroam, guide for connecting (in Swedish), and eduroam resources.
Parameters
The following parameters must be exchanged with Skolfederation for eduroam connected organizations:
Administrative parameters
- Organization name
- Domain name
- Technical contact person (name and email address)
- Administrative contact person (name and email address)
- Email address for abuse related matters
Technical parameters
- Protocol (RADIUS/RADSEC)
- Name and IP addresses of connected servers
- Mutually shared secret (RADIUS) or certificate (RADSEC)
The shared secred is provided by Skolfederation to the technical contact in agreement. If certificate is used the exchange is performed correspondingly.
RADIUS/RADSEC servers
Servers:
For RADIUS, use port 1812 (UDP)
For RADSEC, use port 2083 (TCP)
RADSEC certificate
Certificate file is found here: https://skolfederation.se/app/uploads/2021/10/eduroam-skolfederation-v2-1.crt
eduroam-skolfederation-v2-1.crt
|
|
Acceptance test and connecting
Before the test connection may be put in production an acceptance test must be performed. How the acceptance test is performed depends on if the organization is connecting as eduroam SP and/or IdP.
Connecting eduroam SP
To connect an eduroam SP the connecting organization configures their RADIUS servers with Skolfederation parameters.
The connecting organization is responsible for filtering any harmful attributes in RADIUS responses, such as VLAN- and role allocation.
After configuration a temporary test account is obtained. When Skolfederation and the connecting organization have confirmed successful authentication, and that the network function fulfills the eduroam Policy Service Definition, the systems may be put into production.
Connecting eduroam IdP
To connect an eduroam IdP the connecting organization configures their RADIUS servers to respond to calls from Skolfederation. Connected IdP must fulfill the requirements set in SWAMID eduroam Technology Profile v1.0.
After configuration connecting organization should perform a test of the function. This is performed easiest by testing the connection at another connected eduroam SP.
Resources
Guide
Here you can find a guide containing information and considerations on connecting (in Swedish):
https://skolfederation.se/app/uploads/2014/04/eduroam-v%C3%A4gledning.pdf
Summarized experiences in connecting to eduroam
Linköping municipality shares their experiences in connecting to eduroam in the below document (in Swedish):