TF-Mobility update Klaas.Wierenga@surfnet.nl TF-EMC2, Barcelona 9 September 2005
eduroam: roaming network access Supplicant Authenticator (AP or switch) RADIUS server University A RADIUS server University B User DB User DB Gast piet@university_b.nl SURFnet Employee VLAN Commercial VLAN Central RADIUS Proxy server Student VLAN Trust based on RADIUS plus policy documents (or at least it will be ;-) 802.1X (VLAN assigment) signaling data
Status ~20 countries ~400 institutions Next targets: USA, Japan, Taiwan, Belgium…
Trouble in paradise? AA traffic goes through all intermediate entries Static routes All or nothing authentication Usability Managing and monitoring
Towards a real service (in close cooperation with GN2 JRA5) Managing and monitoring of the infrastructure and the usage Make it easy to find an eduroam hotspot Set standards for SSIDs, ciphers etc. eduroam client And then there is a bit of policy making….
Towards p2p trust? Seperate the trust fabric from the authentication flow Possible candidates: Diameter, DNSsec, Radsec/DNSroam
Eduroam-ng? P2P communication
Mix and match P2P communication