eduroam technical information

On this page you will find technical details on eduroam, guide for connecting (in Swedish), and eduroam resources.

Parameters

The following parameters must be exchanged with Skolfederation for eduroam connected organizations:

Administrative parameters

  • Organization name
  • Domain name
  • Technical contact person (name and email address)
  • Administrative contact person (name and email address)
  • Email address for abuse related matters

Technical parameters

  • Protocol (RADIUS/RADSEC)
  • Name and IP addresses of connected servers
  • Mutually shared secret (RADIUS) or certificate (RADSEC)

The shared secred is provided by Skolfederation to the technical contact in agreement. If certificate is used the exchange is performed correspondingly.

RADIUS/RADSEC servers

Servers:

For RADIUS, use port 1812 (UDP)
For RADSEC, use port 2083 (TCP)

RadSec technical information

RadSec is used for RADIUS communication between participating organisations and the Skolfederation eduroam infrastructure.

RadSec connections are established in both directions. Depending on the direction, Skolfederation acts either as the RadSec server or as the RadSec client.

Connections to Skolfederation

Participating organisations connect to:

r3.eduroam.skolfederation.se:2083
r4.eduroam.skolfederation.se:2083

In this direction:

Participating organisation (RadSec client)
        |
        v
Skolfederation (RadSec server)

The participating organisation must trust and verify the certificate presented by the Skolfederation RadSec servers.

Skolfederation RadSec server certificate

This certificate is presented by Skolfederation when participating organisations connect to r3.eduroam.skolfederation.se and r4.eduroam.skolfederation.se.

Subject: CN=radius.eduroam.skolfederation.se 


-----BEGIN CERTIFICATE-----
MIIGFTCCA/2gAwIBAgIJANFyJ3HDEqw+MA0GCSqGSIb3DQEBCwUAMIGgMQswCQYD
VQQGEwJTRTESMBAGA1UECAwJU3RvY2tob2xtMRIwEAYDVQQHDAlTdG9ja2hvbG0x
FzAVBgNVBAoMDlNrb2xmZWRlcmF0aW9uMSkwJwYDVQQDDCByYWRpdXMuZWR1cm9h
bS5za29sZmVkZXJhdGlvbi5zZTElMCMGCSqGSIb3DQEJARYWaW5mb0Bza29sZmVk
ZXJhdGlvbi5zZTAeFw0yMTA5MjgxMDQ5MDlaFw0zMTA5MjYxMDQ5MDlaMIGgMQsw
CQYDVQQGEwJTRTESMBAGA1UECAwJU3RvY2tob2xtMRIwEAYDVQQHDAlTdG9ja2hv
bG0xFzAVBgNVBAoMDlNrb2xmZWRlcmF0aW9uMSkwJwYDVQQDDCByYWRpdXMuZWR1
cm9hbS5za29sZmVkZXJhdGlvbi5zZTElMCMGCSqGSIb3DQEJARYWaW5mb0Bza29s
ZmVkZXJhdGlvbi5zZTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAMej
axUv2VuYvwELE3gxfPYHTxUn2LRtMa4p87n8bX3UsU2kiud/15fJt6x26RH1TSn1
l+LETa+EUI0DKYapmlt0uMZO9zLRK+HvvdT5M0xEVeN7CAEROvIDBBHcQPaDvm1C
Xb1Kuj0mrF92p99hJvr9ZZNaZ7YbNVeD+CAY1FKjiHHtyzBr+8Zzwq0Q7iPMj/uY
JR3YS1uwdjpcL6mhXpzgPVmK/F82bK0AipB4FdL5qWFWWCaILEqO6jnm8fbRtvJO
bnPDRHzvnQ1UhK2Jy9bngfZofvgT661hcIfFn+syj47OuYC5YoDp4XoCa74tHo4D
vh6ZHvY3/vEI0I4Maj8kLE6kU4ck53DzuAaLL/ZD7Rri3HpOZVchPVTGCG/CH5i0
RphiIc6kXjaUJVoB3xUBPM2EBD3QS4UQTLm3KgQ6xJEKGEDYV5fWkHVmDKoJbsIF
g0UJJ3bONW1EDYqYB0KSfjruumWLQ47eybgX0M61BlEfJBvZXQJroyQTNw/qt0ae
Ek1oEuByPbNY73LvvizJNNoS3Ql3A1EonBhti2l6bxd+fd+SJaBbJ5Il7YOdk1cw
a8bEe9g6P0GhnoxL6ESaf0hjj6FquWZJm3VaiFu/PdVI4/lLCxaKlTFGFPwT38Ps
Kx1j3ng0MOuK6eG9wgzmBqyg17B7NFLQLTZqotZxAgMBAAGjUDBOMB0GA1UdDgQW
BBTtkncImc0NGbKTSLRVBAvKDVf5PjAfBgNVHSMEGDAWgBTtkncImc0NGbKTSLRV
BAvKDVf5PjAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQCQp3L3+ged
xWyKJAWErkpciuYTX6d/xuJVAQy23jzYSAVnfq0QwgeIzuKZ1sKEl+a1UiLkzN82
fULQ0/sILPHoU8v+wr9AYHdJiwpFGdeuxOv5QGTGqblRZlSTeuuo/VuriEhUSKi+
afpObwJHKZmnixmhSMgEXeO0Ft0lBWrvxsYN2n9MzJPV0OrspLvr0AhkjzJAs/7m
uxPIyuFss2sCPiRT4YSTVAIWkPutxTLQeoFsl2oUHNVGVkPrxWhv3fZo85/tAdFS
+mBrNzc19lLK0TvOOCpvDsREQpA6vipormxPKhvyfPGCrBuGzbTnjZ5/MtbWPXyS
FIFNjS486EiGWsSl382O+my8pJsOADpurzj5sjNGC1vl8IzWgsU6LU66AeFI+4xo
6ubv5izHvG2IqPdzGbM2UDU+k+nN/m3bdzoQN7ZFSK8TThSjTBB9zG7jGQjQRKNn
akP+VcdDqJFV/YuWpYMYNgEbQBCs+dKEU5W9STSqjQ+ZhpsJXBq7L8Phmbg5Qxf3
1PKibXiMO7TYRfovIakLw0D8VNMGM/bhLCxI9vPr/mhCUM+S2U6+pSaOVaZtDi0o
2cJ/BG8DIpFx5ejInDe3WVDGLvt3HuFCLlkMsUXAhvrUJlrmUi6BVyI3by2FiBsv
kzlKajVgtanlx0N1AHKDksppk8FEgHO+kw==
-----END CERTIFICATE-----

SHA-256 fingerprint:
9C:CD:45:03:F7:6A:E0:DA:C0:87:A1:DF:66:66:F5:52:5D:89:65:79:25:1C:E8:74:93:57:8A:82:C9:A0:A3:A7

Connections from Skolfederation

Skolfederation also establishes RadSec connections to the participating organisation.

In this direction:

Skolfederation (RadSec client)
        |
        v
Participating organisation (RadSec server)

The participating organisation must trust and verify the certificate presented by the Skolfederation RadSec client.

Skolfederation RadSec client certificate

This certificate is presented by Skolfederation when connecting to the participating organisation's RadSec servers.

Subject: CN=radius.eduroam.skolfederation.se


-----BEGIN CERTIFICATE-----
MIIF/jCCA+agAwIBAgIUIGE07iBnkuE1ZZFLO9pNYlEo9P0wDQYJKoZIhvcNAQEL
BQAwgYMxCzAJBgNVBAYTAlNFMTAwLgYDVQQKDCdTdGlmdGVsc2VuIGbDg8K2ciBJ
bnRlcm5ldGluZnJhc3RydWt0dXIxFzAVBgNVBAsMDlNrb2xmZWRlcmF0aW9uMSkw
JwYDVQQDDCByYWRpdXMuZWR1cm9hbS5za29sZmVkZXJhdGlvbi5zZTAeFw0yNDEw
MDIwNzUyMDZaFw0zNTEwMDUwNzUyMDZaMIGDMQswCQYDVQQGEwJTRTEwMC4GA1UE
CgwnU3RpZnRlbHNlbiBmw4PCtnIgSW50ZXJuZXRpbmZyYXN0cnVrdHVyMRcwFQYD
VQQLDA5Ta29sZmVkZXJhdGlvbjEpMCcGA1UEAwwgcmFkaXVzLmVkdXJvYW0uc2tv
bGZlZGVyYXRpb24uc2UwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDH
5ReszqP9Gnh17tOhOQNvicxEnuD4OjftrvJAQDSiOacEFCOfoUYzrO4R38UmVv4O
toDKpUdpouAd+TBEAfM+SKEg4pS50K4ezoL2/CPiRStr+dCFVRYpbtbYOzn+iY4B
yPhrMzZChSUwlGDLjfSPJnE/jULgQsRzvj7Rs+PQSrhgLuRX0BsE5EHmvGeLZSSy
Vj69Hkg4vrsoMHyPbC3vit+9IZHUnHDXzugGLrFGqvSLG3DI7FKMKcZMuJxRkeev
roFxa7s1nBfosXBfw8FYsC3tj/HRQH6KBtZIC8atRqlk9QIC2VA6WYi+tDfPBDU4
yld9DPE+X9sp8x9IwDc1znWOuxp+EIrDwn/YKDGlu0rDIY65Z4Hla099hVowqfHP
YAmu9EzRGKYyfCzxQlI9ZH7Wwgpyzf4YLPCOCPnaPtx3l0JeqfhwDI/NotepgmVF
DR7vOHzFAfhqu8J+qi62UyemhV38mVIWD+qhNineufAflNA8aClzG6GBwJyU2ovs
bCj9eCUC2GBbursB8rz89U0rJt6a30QiVXPLU+HyhEZQdinceLOiepD38ifUDZaK
++YCNzLWIBSWDp9abp0DISYNyVX7iThXxlDKRYjv41NktJlPFMWj1sGE3NgElLzm
O4VS2SLKxIO4qZow/Xf13Efh82RuTqDmpP2XqQYzEwIDAQABo2gwZjBFBgNVHREE
PjA8ghxyMy5lZHVyb2FtLnNrb2xmZWRlcmF0aW9uLnNlghxyNC5lZHVyb2FtLnNr
b2xmZWRlcmF0aW9uLnNlMB0GA1UdDgQWBBQ2tIml/o3Ou2VHmgW+MEh+XK88tzAN
BgkqhkiG9w0BAQsFAAOCAgEAbgm3VLXEN6fYa3/Ya4V0Jn5FowjrZ9a+GPOnccEk
CEq6jFK+bdPZXj+aS5UeKSvfo/yXGDD74tb1ApxfXTT/7CuiNi1cIvwlyv1wj/RF
SVh7bigg7adOJBTTp0dP7qTyN/eGDgpZPak9DxfOM9htxy56SY4qye/WsQczSRBC
kOhrzPF2Xowp9VNhcLl3sqVKWMaCStueOWi8DxEas1pyZMeQJt2SUhLMvA0jWwej
x3nzmLg1t6SGMD9eZt/mLdak5iBLuE7clRbntvwoxJU5cvCrELxfQo8MVEbeThBn
Md23CYKulMhctGveE3isZQMOdU31Ohyt/NmVU7OCjVqFRm9qoN7J9zeV5a2+04Pz
mkYx35taqreK8jkrzxTvFycXEkEU7/jMCXsbMaQhOyB7l49dZe7c560YYAPDueUY
fJLchw2n/SctSV2HTh2vNVx8G5SpWO0fWoqAT1iXdr5nGlHIHdk4TnNzeAR6FIpf
PuEYtsC4EVjuME3ARiYs0p206s5+kymbEQyG/z9hpEGLEPKRBqEXHPJbeHr7nv8P
vsHvY13fCErJc/1vOxQHK5dT0byOk+8GJenUyRKTLfhIqPAuX6Pnja84Fz+XZ1Sf
PJsnytbT1gNk8TgmJ7aYIDjGuhIi9FIajP6r+TVVz3WH6x3U1v7dIrKUY51tbd8D
VHI=
-----END CERTIFICATE-----
SHA-256 fingerprint:
61:3D:97:0B:DB:D0:A6:24:C4:D2:81:84:20:00:A2:A9:88:10:39:63:C9:1B:88:E5:23:56:C2:56:B9:9F:01:90

Certificate provided by the participating organisation

The participating organisation must provide Skolfederation with the public certificate presented by its RadSec server.

This certificate is used by Skolfederation when establishing RadSec connections to the organisation.

Only the public certificate must be provided. The corresponding private key must never be sent.

Certificate changes

The two RadSec directions have separate certificate configurations and must be handled independently.

If the Skolfederation RadSec server certificate is replaced, participating organisations must update the trust configuration used when connecting to r3.eduroam.skolfederation.se and r4.eduroam.skolfederation.se.

If the Skolfederation RadSec client certificate is replaced, participating organisations must update the trust configuration used for incoming RadSec connections from Skolfederation.

If a participating organisation replaces the certificate presented by its RadSec server, the new public certificate must be provided to Skolfederation before the change is activated.

A successful certificate update in one direction does not mean that the certificate configuration in the opposite direction has been updated.

SHA-256 fingerprints should be compared when verifying that the correct certificate has been installed.

Acceptance test and connecting

Before the test connection may be put in production an acceptance test must be performed. How the acceptance test is performed depends on if the organization is connecting as eduroam SP and/or IdP.

Connecting eduroam SP

To connect an eduroam SP the connecting organization configures their RADIUS servers with Skolfederation parameters.

The connecting organization is responsible for filtering any harmful attributes in RADIUS responses, such as VLAN- and role allocation.

After configuration a temporary test account is obtained. When Skolfederation and the connecting organization have confirmed successful authentication, and that the network function fulfills the eduroam Policy Service Definition, the systems may be put into production.

Connecting eduroam IdP

To connect an eduroam IdP the connecting organization configures their RADIUS servers to respond to calls from Skolfederation. Connected IdP must fulfill the requirements set in SWAMID eduroam Technology Profile v1.0.

After configuration connecting organization should perform a test of the function. This is performed easiest by testing the connection at another connected eduroam SP.

Resources

External resources


  • No labels