{"id":5692,"date":"2019-05-09T15:15:01","date_gmt":"2019-05-09T13:15:01","guid":{"rendered":"https:\/\/blog.rwth-aachen.de\/itc\/?p=5692"},"modified":"2024-02-13T15:18:27","modified_gmt":"2024-02-13T14:18:27","slug":"sicherheitszertifikat-securitycertificate","status":"publish","type":"post","link":"https:\/\/blog.rwth-aachen.de\/itc\/en\/2019\/05\/09\/sicherheitszertifikat-securitycertificate\/","title":{"rendered":"The Security Certificate: Your Key to eduroam"},"content":{"rendered":"<div class=\"twoclick_social_bookmarks_post_5692 social_share_privacy clearfix 1.6.4 locale-en_US sprite-en_US\"><\/div><div class=\"twoclick-js\"><script type=\"text\/javascript\">\/* <![CDATA[ *\/\njQuery(document).ready(function($){if($('.twoclick_social_bookmarks_post_5692')){$('.twoclick_social_bookmarks_post_5692').socialSharePrivacy({\"txt_help\":\"Wenn Sie diese Felder durch einen Klick aktivieren, werden Informationen an Facebook, Twitter, Flattr, Xing, t3n, LinkedIn, Pinterest oder Google eventuell ins Ausland \\u00fcbertragen und unter Umst\\u00e4nden auch dort gespeichert. N\\u00e4heres erfahren Sie durch einen Klick auf das <em>i<\\\/em>.\",\"settings_perma\":\"Dauerhaft aktivieren und Daten\\u00fcber-tragung zustimmen:\",\"info_link\":\"http:\\\/\\\/www.heise.de\\\/ct\\\/artikel\\\/2-Klicks-fuer-mehr-Datenschutz-1333879.html\",\"uri\":\"https:\\\/\\\/blog.rwth-aachen.de\\\/itc\\\/en\\\/2019\\\/05\\\/09\\\/sicherheitszertifikat-securitycertificate\\\/\",\"post_id\":5692,\"post_title_referrer_track\":\"The+Security+Certificate%3A+Your+Key+to+eduroam\",\"display_infobox\":\"on\"});}});\n\/* ]]> *\/<\/script><\/div><p>&nbsp;<\/p>\r\n<div id=\"attachment_16833\" style=\"width: 310px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/blog.rwth-aachen.de\/itc\/files\/2019\/05\/binary-7206880_1280.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-16833\" class=\"wp-image-16833 size-medium\" src=\"https:\/\/blog.rwth-aachen.de\/itc\/files\/2019\/05\/binary-7206880_1280-300x200.jpg\" alt=\"\" width=\"300\" height=\"200\" srcset=\"https:\/\/blog.rwth-aachen.de\/itc\/files\/2019\/05\/binary-7206880_1280-300x200.jpg 300w, https:\/\/blog.rwth-aachen.de\/itc\/files\/2019\/05\/binary-7206880_1280-1024x682.jpg 1024w, https:\/\/blog.rwth-aachen.de\/itc\/files\/2019\/05\/binary-7206880_1280-768x512.jpg 768w, https:\/\/blog.rwth-aachen.de\/itc\/files\/2019\/05\/binary-7206880_1280.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-16833\" class=\"wp-caption-text\">Quelle: <a href=\"https:\/\/pixabay.com\/illustrations\/binary-binary-code-security-7206880\/\">Pixabay<\/a><\/p><\/div>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>Have you ever wondered what a security certificate actually does? And why is it so important? In the following article we would like to give you answers to these questions.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>Our university WLAN eduroam is available on the entire campus of RWTH Aachen University. Even at the end of track 2 at main station you have a connection to the fast and secure network of the university. In total, we expect about 133,000 devices to be connected to the eduroam network.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>But how does the secure connection to eduroam work? After all, the connection to the network takes place automatically as soon as our mobile devices detect a nearby network with the name \u201ceduroam\u201d.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<h3 class=\"wp-block-heading\">What does a security certificate actually do?<\/h3>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>And this is exactly where the security certificate comes into play. Your eduroam access data must be transmitted to the RWTH authentication server (RADIUS). Since this connection is encrypted in eduroam, your access data is secure during the transmission.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\" style=\"text-align: center;\">\r\n<p><em>But do you know if your credentials are sent to the correct authentication server?<\/em><\/p>\r\n<p>&nbsp;<\/p>\r\n<\/blockquote>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<p>&nbsp;<\/p>\r\n<p>This task is performed by the security certificate of the Radius server. If, for example, you have used the CAT tool to configure your eduroam access on your device, the name of the Radius server and the root certificate of the certification chain will be entered\/installed on your device.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>Based on the names, your device checks whether the correct Radius server is addressed. In addition, based on the root certificate, the TLS protocol checks whether the Radius server is using a certificate that was issued by your trusted certification authority (CA).<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>You express this trust when you install the root certificate on your device. This means:<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p style=\"text-align: center;\">Install it once and trust it implicitly every time you connect.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>With this root certificate, a conversion is now necessary. The \u201cDeutsche Telekom Root CA 2\u201c certificate expires on Tuesday, July 9, 2019, at 23:59:00 GMT. This means, all eduroam devices, which only trust this certificate, will no longer be able to access the network after July 7, 2019, because the connection to the Radius server is no longer trusted.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>But don\u2019t worry, because the Radius server at RWTH is already working with both security certificates attached to different chains. The old one, which expires on July 09, 2019, and the new one, which is valid until October 1, 2033.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>You can already switch to the new chain by changing the eduroam configuration of your devices to the new certificate.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<h3 class=\"wp-block-heading\">Why is it so important to change the access data?<\/h3>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>A further security aspect for the protection of your data is to encrypt it. In principle, it is currently still possible to use eduroam access data to draw conclusions about your personal information. The <a href=\"http:\/\/www.rwth-aachen.de\/eduroam\">eduroam Device Manager<\/a> provides a remedy by generating individual access data for each of your devices \u2013 without revealing your user name or password.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>Therefore, the login will be changed on June 04, 2019. This in connection of the certificate conversion. A connection to the eduroam network is then only possible with secure access data from the eduroam Device Manager, which does not allow any inference to personal information (<em>e.g. your user ID ab123456@rwth-aachen.de<\/em>). Here as well, it is possible and sensible to change the access data as soon as possible.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>We attach great importance to security and want you to remain online. For this reason, we already recommend creating secure access data with the eduroam Device Manager in conjunction with the new security certificate for your mobile devices.<\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p style=\"text-align: center;\"><em>We are aware that all of this means additional work for you, so we have put a lot of effort into the instructions. You can find out how to safely configure eduroam on <a href=\"https:\/\/help.itc.rwth-aachen.de\/en\/service\/1hroqqbju4g2t\/\">IT Center Help<\/a>.<\/em><em><br \/><\/em><\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p><strong>We thank you for your understanding and look forward to your feedback!<\/strong><\/p>\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n<p>Responsible for the content of this article is <a href=\"http:\/\/www.itc.rwth-aachen.de\/cms\/IT-Center\/IT-Center\/Team\/~epvp\/Mitarbeiter-CAMPUS-\/?gguid=0x076EFD6C62ADCF4D868FB7134A14B07C&amp;allou=1\">Nicole Filla<\/a> with the kind support of <a href=\"http:\/\/www.itc.rwth-aachen.de\/cms\/IT-Center\/IT-Center\/Team\/~epvp\/Mitarbeiter-CAMPUS-\/?gguid=0x6317B0C5B8127D4E8C1538F3CF93C9F0&amp;allou=1\">Ekaterini Papachristou<\/a>.<\/p>\r\n<!-- \/wp:post-content -->\r\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>Sorry, this entry is only available in Deutsch.<\/p>\n","protected":false},"author":1413,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"c2c_always_allow_admin_comments":false,"footnotes":""},"categories":[314,315],"tags":[],"class_list":["post-5692","post","type-post","status-publish","format-standard","hentry","category-it-sicherheit","category-services-support"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/posts\/5692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/users\/1413"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/comments?post=5692"}],"version-history":[{"count":16,"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/posts\/5692\/revisions"}],"predecessor-version":[{"id":18559,"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/posts\/5692\/revisions\/18559"}],"wp:attachment":[{"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/media?parent=5692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/categories?post=5692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.rwth-aachen.de\/itc\/en\/wp-json\/wp\/v2\/tags?post=5692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}