60 likes | 177 Views
. An eduroam-client ? Barcelona, 6th of September 2005 David Simonsen,UNI-C. "eduroam is a registered trademark of TERENA. David Simonsen is independent of TERENA.". Yet Another Client (YAC)... WHY ?!?!?!. eduroam must be easy to use eduroam must be safe
E N D
An eduroam-client ? Barcelona, 6th of September 2005 David Simonsen,UNI-C "eduroam is a registered trademark of TERENA. David Simonsen is independent of TERENA."
Yet Another Client (YAC)...WHY ?!?!?! • eduroam must be easy to use • eduroam must be safe • Today Windows does not support TTLS • Windows cannot automatically try different encryption algorithms (WPA Supplicant can) • eduroam is a location based service • eduGAIN will most likely need some sort of client software - perhaps it could be an updated version of the eduroam-client?
Possible solution • Take the WPA-supplicant source • Develop a nice GUI • Make it easily installable (Windows, Mac, Linux) • Make the it ’plugable’ (phonebook, iPass, GPS, eduGAIN etc.)
Possible funding • Nordunet3-programe (announced in April, deadline for call: 15th of October) • Géant2 ? • Any other suggestions?
Nordunet3 Nordunet3 will sponsor research in many aspects of security, including: ・ Safety ・ Privacy ・ Anonymity, anonymous data access ・ Authorization and Authentication ・ Trust ・ Identity management ・ Inter-organization and international resource sharing. ・ Encryption ・ Digital signatures ・ Legal issues ・ Scalable security architectures ・ Security in very-high-speed networks ・ Security of networked computing and storage platforms ・ Security aspects of roaming and mobile network use ・ Wireless Security
Josh says... Just to summarise: 1. I fully endorse the concept of an eduroam supplicant based on the wpa_supplicant code. FYI, I was quoted $8K (one man month) by TheKompany for a Linux/Windows GUI cloning the Funk Odyssey supplicant. The wpa_supplicant code has progressed significantly since, and so this should be even cheaper now. 2. I understand the attraction of using the eduroam supplicant as a means to get an AAI client onto users' machines. However, I am rather doubtful this will be a successful strategy, for the following reasons: a) Many Institutions won't deploy a third-party supplicant, even if it's free (this was a result from a UK survey). They prefer to suffer the existing Windows supplicant until Longhorn, when they hope it will be better! b) Many Institutions will be locked into their Network Addmission vendor's supplicant (Microsoft, Cisco, Funk) because this functionality is seen as very important by some Institutions. 3. I like the concept of adding other eduroam funtionality (ie. the WAP database) to the supplicant, providing it's reasonably modular. (so that Institutions can choose which bits they want to give to users, and to prevent bloat). 4. I am trying to get UKERNA to fund the wpa_supplicant development, but open-source funding is a new concept to them :-/. I am considering whether to ask UK Institutions individually for donations instead (I once managed to raise $60K for a PocketPC PPPoE client this way!), although there is a lot of work & risk to this approach. I hope you have fun in Barcelona!