The Radius server certificate was replaced on 14/01/2025. If your device prompts you to check a certificate for eduroam or to trust a new certificate, you should check the fingerprint of the certificate. Most devices should continue to connect to eduroam automatically. More details on the behaviour on the individual devices can be found here: |
Details: Fingerprint Certificate Radius-Server
Depending on the device, you may have to reconnect to eduroam, select the certificate again or trust the certificate.
sha1 Fingerprint=22:8B:F4:7C:AC:00:BD:F6:77:F9:39:78:B5:AF:BF:66:C0:5C:84:D6
sha256 Fingerprint=98:A9:22:F8:DC:C9:92:EA:19:B1:97:5A:44:D7:CA:01:30:4E:CB:2F:14:69:79:18:5F:69:8A:25:03:E1:05:88
sha512 Fingerprint=3D:FA:3B:AA:D4:41:B0:4F:AA:C6:F1:58:CA:D3:A2:B6:1A:23:52:B2:9E:92:6D:C0:2B:B5:ED:50:8D:1D:FF:34:29:FC:D3:B5:6F:4C:8D:7F:A0:85:8B:38:B0:46:C5:17:98:2A:72:25:41:42:5D:39:BA:40:1D:9C:F3:14:24:64
macOS
- Zertifikat einblenden to check certificate
- Continue to trust the certificate
iPhone und iPad
- Display certificate to check the certificate
- Accept certificate to trust the certificate
Windows
- Show certificate details to check the certificate
- Connect to trust the certificate
This tutorial describes how to set up the Wi-Fi eduroam on android.
Android is used by many different manufactureres and therefore can look very different. We can't offer instructions for every device.
Step-by-step description[Bearbeiten | Quelltext bearbeiten]
Create certificate[Bearbeiten | Quelltext bearbeiten]
Bevore setting up eduroam, we must create and install a certificate. You can use mobile data for this. Otherwise use webauth.
Visit the Serviceportal and log in with your Uni-Account.
We recomend using the "Google-Chrome-Browser". Other browsers may also work.
- Click on the displayed icon.
- Click on "User Selfcare"
- Click on "Network Settings".
- Click on "Create network certificate".
- Name your certificate.
- Choose "Version 1" as the data format.
- Click on "Send Certificate".
Hinweis: Create a certificate for every device. A device isn't used anymore? A device got lost or stolen? Retract your certificate!
Install user certificate[Bearbeiten | Quelltext bearbeiten]
- A new certificate was created.
- Copy the "Import Passwort".
- Click on "Download certificate".
- Use your "Import Passwort" to open the certificate.
- Click on "Ok".
The dialogue is not displayed?
Normally, the certificate import assistant opens now. If this isn't the case: Swipe down from the top. Your certificate should appear as a download in the infocenter. Open it with a click.
- Name your certificate in order to find it again - e.g. Eduroam.
- Choose "WLAN" or "Wi-Fi".
- Click on "Ok".
- Copy the identifier named "Identität".
- We will need it in the next step.
Set up eduroam[Bearbeiten | Quelltext bearbeiten]
After installing the certificate, you can set up eduroam.
- Open the Wi-Fi settings
- Select "eduroam".
Choose the following settings:
- EAP-Methode: TLS
- Identitiät: Insert from clipboard. We copied it in the step before. Alterternatively, you can enter benutzername@uni-paderborn.de. Replace benutzername with your personal username for the Uni-Account.
- CA-Zertifikat: Systemzertifikate verwenden
- Domäne: radius.uni-paderborn.de
- Benutzerzertifikat: eduroam
Info: If you can't find these setting - Click on Additional settings at first.
No entry Use System certificates?
If the option "Use system certificates" is not available, you need to install the CA certificate first. Visit
Install the T-TeleSec GlobalRoot Class 2 certificate.
- Name the certificate - e.g. Root UPB.
- Choose WLAN or Wi-Fi.
- Click on Ok.
To install a system certificate, your device needs to be protected by pin, fingerprint or a different safety method. Don't deactivate the safety method. Otherwise, you need to set up eduroam again.
After installing the certificate, you can set up eduroam.
- Open the Wi-Fi settings
- Select "eduroam".
Choose the following settings:
- EAP-Method: TLS
- Identity: * Identitiät: Insert from clipboard. We copied it in the step before. Alterternatively, you can enter benutzername@uni-paderborn.de. Replace benutzername with your personal username for the Uni-Account.
- CA Certificate: Root UPB
- Domain: radius.uni-paderborn.de
- User certificate: eduroam
Delete webauth[Bearbeiten | Quelltext bearbeiten]
- If you used webauth - Delete it afterwards.
- Log press on webauth and click on Delete.
- This can also be labled as Forget.
Alternatives[Bearbeiten | Quelltext bearbeiten]
On Android 9 the CA certificate may not be needed. You can choose "Use network certificates" instead.
Troubleshooting[Bearbeiten | Quelltext bearbeiten]
No connection to eduroam
Try the following steps:
- Deactivate and activate Wi-Fi
- Deactivate and activate Airplane Mode
- Perform a restart.
Certificate can't be installed
Do you get the error message "Certificate can't be read"? Try to install the certificate manually. Download the certificate. Ignore the error message.
Open the settings. The path can differ but open
Settings /Additional Settings / Security
Click on Install certificates from SD-Card and install the downloaded certificates.
Info: Can't find the option in the menu? Search for it.
Certificate: Password wrong
Do you get the error message "Password wrong". Don't use the clipboard but type in the password manually.
That does't help either? There is no fix for this problem yet.