Gemeinsame Systemgruppe IfI/b-it

You are here: aktuelles » en » wifistd

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
en:wifistd [2024-05-08 11:46] Thomas Thielen:wifistd [2025-11-24 08:07] (current) Thomas Thiel
Line 1: Line 1:
-==== WiFi Access ====+===== WiFi Access =====
  
 Everyone who is in possession of valid login credentials to central systems of the c.s. dept. or the b-it has the opportunity to use our wifi networks to access the local resources and of course the internet. Please follow the instructions provided here to gain access to the wifi network. Everyone who is in possession of valid login credentials to central systems of the c.s. dept. or the b-it has the opportunity to use our wifi networks to access the local resources and of course the internet. Please follow the instructions provided here to gain access to the wifi network.
Line 17: Line 17:
 \\ \\
  
-All certificates are signed by "GEANT OV RSA CA 4", GEANT Vereniging, NL.+The local certificate is signed by "GEANT OV RSA CA 4", GEANT Vereniging, NL.
  
-=== Generic Parameters ===+**Starting with 2025-11-28, new fingerprints will be valid:** 
 + 
 +^ Hashtype ^ Fingerprint ^ 
 +| MD5    | 01:7D:5A:E2:CA:22:3F:63:F6:7C:67:AB:2A:37:58:F5 | 
 +| SHA1   | 3D:04:22:7B:BF:FE:85:C8:03:5C:4B:F0:C0:96:5E:A6:C0:F0:EA:6B | 
 +| SHA256 | 2A:92:8F:51:1F:A3:3B:3B:49:78:F5:39:2F:09:00:07:80:D7:C7:F7:61:1D:42:1B:25:AB:B5:23:4D:31:0D:B3 | 
 +\\ 
 + 
 +The new certificate will be signed by "GEANT TLS RSA 1", the Hellenic Academic and Research Institutions CA. 
 + 
 +==== Generic Parameters ====
  
 Please use the following connection parameters: Please use the following connection parameters:
Line 29: Line 39:
 | Keytype                                            | AES                                                        |  | Keytype                                            | AES                                                        | 
 | Phase 2 Authentification                           | PAP                                                        | | Phase 2 Authentification                           | PAP                                                        |
-| CA Certificate                                     | use system certificates (or [[https://gsg.cs.uni-bonn.de/files/chainGEANT.crt|GEANT OV RSA CA 4]] if this does not work for you) |+| CA Certificate                                     | use system certificates (or [[https://gsg.cs.uni-bonn.de/files/chainGEANT.crt|GEANT OV RSA CA 4]] if this does not work for you, or beginning with 2025-11-28: [[https://gsg.cs.uni-bonn.de/files/chainHARICA.crt|GEANT TLS RSA 1]]) |
 | valid CN (Common Name) Radius-Server Certificates  | radius.informatik.uni-bonn.de                      | | valid CN (Common Name) Radius-Server Certificates  | radius.informatik.uni-bonn.de                      |
 | Anonymous Identity                                 | anonymous@(bit%%|%%informatik)((only use your domain here, i.e anonymous@bit.uni-bonn.de for b-it accounts or anonymous@informatik.uni-bonn.de for C.S. Dept. Accounts. Use anonymous@wlan.informatik.uni-bonn.de for the [[en:wifialt|alternative wifi password]].)).uni-bonn.de                    | | Anonymous Identity                                 | anonymous@(bit%%|%%informatik)((only use your domain here, i.e anonymous@bit.uni-bonn.de for b-it accounts or anonymous@informatik.uni-bonn.de for C.S. Dept. Accounts. Use anonymous@wlan.informatik.uni-bonn.de for the [[en:wifialt|alternative wifi password]].)).uni-bonn.de                    |
Line 36: Line 46:
 | Authentification Server                            | radius.informatik.uni-bonn.de | | Authentification Server                            | radius.informatik.uni-bonn.de |
  
-=== Windows 10 and above ===+==== Windows 10 and above ====
  
 If you want to use our wifi network on your Windows System (for all releases starting with Windows Vista), ​we provide a  If you want to use our wifi network on your Windows System (for all releases starting with Windows Vista), ​we provide a 
Line 43: Line 53:
 After the installation you just have to issue your username (including the correct domain, i.e. username@informatik.uni-bonn.de for the c.s. dept. or username@bit.uni-bonn.de. Please use username@wlan.informatik.uni-bonn.de for the [[en:wifialt|alternative wlan password]].) and of course your password. Please verify the server certificate against the fingerprints issued on the top of this page. After the installation you just have to issue your username (including the correct domain, i.e. username@informatik.uni-bonn.de for the c.s. dept. or username@bit.uni-bonn.de. Please use username@wlan.informatik.uni-bonn.de for the [[en:wifialt|alternative wlan password]].) and of course your password. Please verify the server certificate against the fingerprints issued on the top of this page.
  
-=== Windows 7 ===+==== Windows 7 ====
  
 Users of windows 7 do not have the luxury of native TTLS Support, so it has to be provided by an external supplicant. One of these supplicants is GEANTLink, which is part of the [[https://cat.eduroam.org/|eduroam CAT Tool]], which is used to prepare your system for eduroam usage. If you do not want to use eduroam at all, you can install a standalone version of GEANTLink by downloading one of their official binaries from [[https://github.com/Amebis/GEANTLink/releases|here]].  Users of windows 7 do not have the luxury of native TTLS Support, so it has to be provided by an external supplicant. One of these supplicants is GEANTLink, which is part of the [[https://cat.eduroam.org/|eduroam CAT Tool]], which is used to prepare your system for eduroam usage. If you do not want to use eduroam at all, you can install a standalone version of GEANTLink by downloading one of their official binaries from [[https://github.com/Amebis/GEANTLink/releases|here]]. 
Line 51: Line 61:
 After the installation you just have to issue your username (including the correct domain, i.e. username@informatik.uni-bonn.de for the c.s. dept. or username@bit.uni-bonn.de. Please use username@wlan.informatik.uni-bonn.de for the [[en:wifialt|alternative wlan password]].) and of course your password. After the installation you just have to issue your username (including the correct domain, i.e. username@informatik.uni-bonn.de for the c.s. dept. or username@bit.uni-bonn.de. Please use username@wlan.informatik.uni-bonn.de for the [[en:wifialt|alternative wlan password]].) and of course your password.
  
-=== Android ===+==== Android ====
  
 {{ :de:android12.jpg?direct&300| }} {{ :de:android12.jpg?direct&300| }}
Line 59: Line 69:
 If your system cannot use the root certificates installed to verify the wifi certificate, you have to download the necessary root certificate via mobile network and install it as a wifi Certificate. Do not install it as a VPN certificate, it will not be available to you for wifi configuration! If your system cannot use the root certificates installed to verify the wifi certificate, you have to download the necessary root certificate via mobile network and install it as a wifi Certificate. Do not install it as a VPN certificate, it will not be available to you for wifi configuration!
  
-=== MacOS/IOS ===+==== MacOS/IOS ====
 [[ :en:macos8021xstepbystep|Click here for a step-by-step installation guide for MacOS ]]  \\  [[ :en:macos8021xstepbystep|Click here for a step-by-step installation guide for MacOS ]]  \\ 
 [[ :en:ios8021xstepbystep|Click here for a step-by-step installation guide for iOS ]]  [[ :en:ios8021xstepbystep|Click here for a step-by-step installation guide for iOS ]]