10 Years of eduroam (from an idea to a product) Miroslav Milinović University Computing Centre, University of Zagreb, Zagreb, Croatia <miro@srce.hr> TNC 2012 Reykjavik, Iceland, May 2012
It all started with ... http://www.terena.org/activities/tf-mobility/start-of-eduroam.pdf
(inter-NREN) roaming requirements Identify users uniquely at the edge of the network Enable guest usage Scalable local user administration and authentication Easy to install and use at the most one-time installation by the user Open (http://www.terena.org/activities/tf-mobility/deliverables/delC/DelC1-4.pdf)
Web-based solution
VPN-based solution
The solution: eduroam XYZnet Commercial Employee VLAN VLAN Student Supplicant Authenticator (AP or switch) RADIUS server University A RADIUS server University B User DB User DB user joe@university_b.hr XYZnet Employee VLAN Commercial VLAN Central RADIUS Proxy server Student VLAN signalling data
Radius proxy hierarchy SURFnet FUNET (DFN) Srce Radius proxy hierarchy Participation guidelines are being drafted Aim is to increase membership. Spain, Norway, Slovenia, Czech Republic & Greece have indicated their willingness to join. University of Southampton FCCN RADIUS Proxy servers connecting to a European level RADIUS proxy server February 2004
GEANT2: from a pilot to a service JRA5 (2004) SA5 (2007) European eduroam Policy v .1.0 (January 2008) Supporting services European eduroam confederation Service officially started on September 1, 2008 http://www.eduroam.org
Objectives/goals build and maintain (European) roaming service: provide secure, consistent and uniform network access service inside the boundaries of the confederation motto: “open your laptop and be online” eduroam infrastructure: technology infrastructure: ETLRSs, FLRSs, IdPs and SP RADIUS servers, network access elements (APs/switches) supporting infrastructure: monitoring service, eduroam database, TTS, eduroam web site, mailing lists
www.eduroam.org
eduroam growing ... Global eduroam Governance committee (GeGC) eduroam Compliance Statement, October 2011 50+ countries European confederation (43 countries) Australia, Canada, Japan, USA, ... Asia & Pacific, Latin America, Africa, ... 5000+ service locations only in Europe cumulative stats from 20+ European countries total of over 250 million successful authN (≈ 6% is international) ETRLS servers (March 2012): 3.000.000+ successful authN ≈ 400.000 CSI/days (device/days) eduroam is ranked as 27th most widely used SSID (http://www.wigle.net/gps/gps/main/ssidstats)
... and this is just a start ... ongoing deployment ... new members increasing coverage inside the countries that have joined ... & development core technology (RadSec/dynamic discovery, EAP types, ...) supporting services (CAT, eduroam companion, diagnostics, ...)