Zeile 51: | Zeile 51: | ||
===Set up Eduroam=== | ===Set up Eduroam=== | ||
[[Datei:Eduroam unter Linux_01.png|left|mini|without|350px|status menu]] | [[Datei:Eduroam unter Linux_01.png|left|mini|without|350px|status menu]] | ||
− | <br> | + | <br clear=all> |
* Open the status menu. | * Open the status menu. | ||
* Select '''"WLAN Netzwerke auswählen"'''. | * Select '''"WLAN Netzwerke auswählen"'''. | ||
Zeile 57: | Zeile 57: | ||
[[Datei:Eduroam unter Linux_02.png|left|mini|without|350px|WLAN settings]] | [[Datei:Eduroam unter Linux_02.png|left|mini|without|350px|WLAN settings]] | ||
− | <br> | + | <br clear=all> |
* Choose eduroam. | * Choose eduroam. | ||
<br clear=all> | <br clear=all> | ||
Zeile 63: | Zeile 63: | ||
Set up eduroam as follows: | Set up eduroam as follows: | ||
[[Datei:Eduroam unter Linux_03.png|links|mini|without|350px|eduroam setup]] | [[Datei:Eduroam unter Linux_03.png|links|mini|without|350px|eduroam setup]] | ||
− | <br> | + | <br clear=all> |
* '''Security:''' WPA & WPA2 Enterprise | * '''Security:''' WPA & WPA2 Enterprise | ||
* '''Legitimation:''' TLS | * '''Legitimation:''' TLS |
Version vom 2. Juni 2024, 17:34 Uhr
The Radius Server certificate was changed on February 15, 2024. You do not need to install a new user certificate! Most devices should still connect to eduroam automatically. If your device asks whether you want to trust the new certificate, you should check the certificate's fingerprint. If the certificate is not present on your device, you can download it here:
SHA1 Fingerprint=F0:CB:92:A7:B6:2E:21:00:97:C7:00:88:F2:6D:CD:EB:D6:D6:D6:E5
SHA256 Fingerprint=40:96:14:4C:DA:39:8E:A5:15:85:5D:32:4A:04:E0:5C:E4:E1:9E:1E:EB:BA: DD:27:A0:30:8C:E4:20:52:48:48
SHA512 Fingerprint=00:B8:D3:4A:60:0A:7C:2A:AC:84:11:92:90:DA:C5:14:F7:05:79:86:23:4E: D2:44:F7:0D:D7:6A:FF:CA:26:A2:8E:AD:87:7F:79:5D:64:5E:24:8C:19:41:E0:0F:16: 1F:97:AE:6E:93:61:E4:F1:93:3C:47:47:75:53:7C:F5:25
These instructions for setting up the eduroam WLAN at the University of Paderborn apply to devices with Linux via the user interface (GUI). As an example, the network is set up here under Ubuntu 14.04 LTS with Gnome Desktop. Depending on the Linux version, the settings may vary slightly. Please note that the Notebook Café does not offer immediate Linux support.
What to do?[Bearbeiten | Quelltext bearbeiten]
- Create your personal university network certificate
- <optional> Download the root certificate. This is a standard root certificate, so it should already exist.
- Set up the eduroam network.
- Delete any existing webauth profile so that the device automatically connects to eduroam.
- Special case: Depending on the Linux version, uni-paderborn.de must be entered under Domain/domain.
Step-by-step instructions[Bearbeiten | Quelltext bearbeiten]
Provide certificates[Bearbeiten | Quelltext bearbeiten]
Access using a browser such as B. Firefox or Internet Explorer, open the service portal, log in with your user name and password and apply for a new certificate under "WLAN". Enter the name of the device on which the certificate is to be installed.
A password will then be automatically generated for the certificate and displayed on the following page. It is best if the password is copied for further installation.
- Click "Neues Zertifikat erstellen".
- Give the certificate a unique name (Ex: Laptop xy)
- Select Version 2 as the file format.
- Then click on "Neues Zertifikat zusenden".
- A new network certificate has been created for you.
- First copy the Import Password to the clipboard.
- Now click on "Netzwerkzertifikat herunterladen".
- Then click "CA-Zertifikat herunterladen".
Save both certificates e.g. B. in your user folder or another safe location. Do not delete/move this folder!
Set up Eduroam[Bearbeiten | Quelltext bearbeiten]
- Open the status menu.
- Select "WLAN Netzwerke auswählen".
- Choose eduroam.
Set up eduroam as follows:
- Security: WPA & WPA2 Enterprise
- Legitimation: TLS
- Identity: <username>@uni-paderborn.de (replace <username> with your university account
- Domain (if available): radius.uni-paderborn.de
- CA Certificate:' Select the USERTrust RSA Certification Authority certificate (USERTrustRSACertificationAuthority.crt).
- Password CA certificate: Remains blank.
- User certificate: Select your personal network certificate (the file that ends in .p12 and contains your university account username).
- User certificate password: Remains blank.
- Secret user key: Is usually automatically filled with "User certificate" - otherwise insert it yourself
- User key password: Import password for your personal network certificate.
- <variable> domain:
- uni-paderborn.de (Some Linux versions require this entry)
- radius.uni-paderborn.de (or this one)
- <leave blank> (or something like that, if it shows at all)
Troubleshooting[Bearbeiten | Quelltext bearbeiten]
Add manually[Bearbeiten | Quelltext bearbeiten]
You may also be able to add the eduroam network manually:
- Connection name: Can be freely selected
- SSID: eduroam
- See above for remaining settings.
Ubuntu[Bearbeiten | Quelltext bearbeiten]
Some customers report problems setting up eduroam on Ubuntu 22.04 and newer. The problem is described here:
Attention: The following solution suggestion comes from a customer. Use at your own risk. There was no examination by the ZIM. |
1) Find wpa_supplicant service file with `systemctl status wpa_supplicant`.
For me, the path is "/lib/systemd/system/wpa_supplicant.service"
2) In that file, (with superuser rights), add the line
`Environment="OPENSSL_CONF=/usr/lib/ssl/openssl.cnf"`
3) Backup old config:
`sudo cp /usr/lib/ssl/openssl.cnf /usr/lib/ssl/openssl.cnf.backup`
4) Modify "openssl.cnf" like follows:
a) Below "[openssl_init]" add the line "ssl_conf = ssl_sect".
b) At the end of the file, add
[ssl_sect]
system_default = system_default_sect
[system_default_sect]
Options = UnsafeLegacyRenegotiation
CipherString = DEFAULT:@SECLEVEL=1
5) Restart the service `sudo systemctl restart wpa_supplicant.service`.
If that doesn't work, reboot.