eduroam technical information
On this page you will find technical details on eduroam, guide for connecting (in Swedish), and eduroam resources.
Parameters
The following parameters must be exchanged with Skolfederation for eduroam connected organizations:
Administrative parameters
- Organization name
- Domain name
- Technical contact person (name and email address)
- Administrative contact person (name and email address)
- Email address for abuse related matters
Technical parameters
- Protocol (RADIUS/RADSEC)
- Name and IP addresses of connected servers
- Mutually shared secret (RADIUS) or certificate (RADSEC)
The shared secred is provided by Skolfederation to the technical contact in agreement. If certificate is used the exchange is performed correspondingly.
RADIUS/RADSEC servers
Servers:
For RADIUS, use port 1812 (UDP)
For RADSEC, use port 2083 (TCP)
RadSec technical information
RadSec is used for RADIUS communication between participating organisations and the Skolfederation eduroam infrastructure.
RadSec connections are established in both directions. Depending on the direction, Skolfederation acts either as the RadSec server or as the RadSec client.
Connections to Skolfederation
Participating organisations connect to:
r3.eduroam.skolfederation.se:2083
r4.eduroam.skolfederation.se:2083
In this direction:
Participating organisation (RadSec client)
|
v
Skolfederation (RadSec server)
The participating organisation must trust and verify the certificate presented by the Skolfederation RadSec servers.
Skolfederation RadSec server certificate
This certificate is presented by Skolfederation when participating organisations connect to r3.eduroam.skolfederation.se and r4.eduroam.skolfederation.se.
Subject: CN=radius.eduroam.skolfederation.se
|
|
Connections from Skolfederation
Skolfederation also establishes RadSec connections to the participating organisation.
In this direction:
Skolfederation (RadSec client)
|
v
Participating organisation (RadSec server)
The participating organisation must trust and verify the certificate presented by the Skolfederation RadSec client.
Skolfederation RadSec client certificate
This certificate is presented by Skolfederation when connecting to the participating organisation's RadSec servers.
Subject: CN=radius.eduroam.skolfederation.se
|
|
Certificate provided by the participating organisation
The participating organisation must provide Skolfederation with the public certificate presented by its RadSec server.
This certificate is used by Skolfederation when establishing RadSec connections to the organisation.
Only the public certificate must be provided. The corresponding private key must never be sent.
Certificate changes
The two RadSec directions have separate certificate configurations and must be handled independently.
If the Skolfederation RadSec server certificate is replaced, participating organisations must update the trust configuration used when connecting to r3.eduroam.skolfederation.se and r4.eduroam.skolfederation.se.
If the Skolfederation RadSec client certificate is replaced, participating organisations must update the trust configuration used for incoming RadSec connections from Skolfederation.
If a participating organisation replaces the certificate presented by its RadSec server, the new public certificate must be provided to Skolfederation before the change is activated.
A successful certificate update in one direction does not mean that the certificate configuration in the opposite direction has been updated.
SHA-256 fingerprints should be compared when verifying that the correct certificate has been installed.
Acceptance test and connecting
Before the test connection may be put in production an acceptance test must be performed. How the acceptance test is performed depends on if the organization is connecting as eduroam SP and/or IdP.
Connecting eduroam SP
To connect an eduroam SP the connecting organization configures their RADIUS servers with Skolfederation parameters.
The connecting organization is responsible for filtering any harmful attributes in RADIUS responses, such as VLAN- and role allocation.
After configuration a temporary test account is obtained. When Skolfederation and the connecting organization have confirmed successful authentication, and that the network function fulfills the eduroam Policy Service Definition, the systems may be put into production.
Connecting eduroam IdP
To connect an eduroam IdP the connecting organization configures their RADIUS servers to respond to calls from Skolfederation. Connected IdP must fulfill the requirements set in SWAMID eduroam Technology Profile v1.0.
After configuration connecting organization should perform a test of the function. This is performed easiest by testing the connection at another connected eduroam SP.