Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from...

68
Workshop roaming services: eduroam / govroam Belnet Nicolas Loriau Brussels March 2016

Transcript of Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from...

Page 1: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Workshop roaming services:

eduroam / govroam Belnet – Nicolas Loriau

Brussels – March 2016

Page 2: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Overview of Belnet Services

Page 3: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Overview of Belnet Services

Standard Services « Plus » Services

On demand

« Plus » Services

Associated cost

• Belnet Connectivity

• Internet Connectivity

• IPv4 and IPv6

• DNS Services

• NTP

• Monitoring

• Service desk 24/7

• Workshops

• Back-up Internet

connectivity

• RRN Connectivity

• eduroam

• Belnet R&E Federation

• Multipoint

• Belnet Leased Lines

• Multimedia Transport

Service

• govroam

• Domain Name Registration

• Digital Certificates

• Antispam Pro

• Belnet Cloud Storage

• Belnet Cloud computing

Netw

ork

S

erv

ices

Page 4: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”
Page 5: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

What is it?

• GOVernment ROAMing

• Simple and secure

access to wifi network

• Belnet initiative based on

eduroam technologies

• For governmental

institutions,

administrations, …

• http://www.govroam.be

Belnet - Workshop govroam 31/03/2016

• EDUcation ROAMing

• Simple and secure

access to wifi network

• Terena project to

provide students

access to internet

• For research and

education institutions

• http://www.eduroam.be

Page 6: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Why ?

• Increased Mobility:

users can make use of Wifi infrastructure at other members

• Easy:

users only need their home organization account to login

• Secure:

centralized accounts, no local copies

• Cost effective:

reduce 3G/4G cost when moving between offices

Belnet - Workshop govroam 31/03/2016

Page 7: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Technical framework

Page 8: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Technical infrastructure

Technical Framework

– Principles

– Components

– Authentication flow

Demo

– Objectives

– Test with Windows server 2012 and NPS

Belnet - Workshop govroam 31/03/2016

Page 9: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Principles

To install roaming services, you need:

– Wi-Fi access points and controllers and/or 802.1x switches

– RADIUS server

– User database / LDAP / AD

Based on a hierarchy of RADIUS servers

– Your only point of contact is Belnet

Belnet - Workshop govroam 31/03/2016

Page 10: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Principles

It is:

– A trust-based relationship between members

– An agreement on roaming technologies

Chain of trust:

– All direct peers must be known beforehand

– A shared secrets must be enabled “out-of-band”

– Agreement on authentication protocols & methods

Belnet - Workshop govroam 31/03/2016

Page 11: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Principles Hierarchy of authentication servers

Belnet - Workshop govroam 31/03/2016

AS

Institution-A.be

AS

Institution-B.be

Belgian

Top-Level AS

“Federation”

“Institution”

Page 12: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Principles Hierarchy of authentication servers eduroam

Belnet - Workshop govroam 31/03/2016

Page 13: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Components

Client / Supplicant

– SW on end user's device which handles network authentication

– Minimum requirements: WPA, EAP-TTLS, PEAP enabled

Belnet - Workshop govroam 31/03/2016

Page 14: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Components

Network Access Server / Authenticator / Service

Provider

– IEEE 802.1X enabled switch or wireless access point which

provides Clients access to the (W)LAN

– Seperate VLAN for home and visiting end users

Belnet - Workshop govroam 31/03/2016

Page 15: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Components

Authentication Server / Identity Provider

– Remote Authentication Dial In User Service compliant (RFC

2865/2866)

– NOT a user database

– Authenticates home end users against local user database

– Forwards requests of visiting end users

– Softwares:

• Radiator

• FreeRADIUS

• Windows server with NPS (from 2008R2)

• Others

Belnet - Workshop govroam 31/03/2016

Page 16: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Components

User identity source

– LDAP/AD

– Local database / SQL

Belnet - Workshop govroam 31/03/2016

Page 17: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Protocols and Methods

EAP Framework

– Extensible Authentication Protocol (RFC 5247)

– NOT a wire protocol nor an authentication mechanism

– Defines authentication data formats

– Negotiates which authentication method/type should be used

Belnet - Workshop govroam 31/03/2016

Page 18: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Protocols & Methods

EAP Methods/Types "How does EAP authenticate"

– Uses EAP framework to remotely authenticate end user's credentials to

his home institute's Identity Provider

– 40+ different methods exit > use common secure ones!

• Outer Authentication: EAP-TTLS (RFC 5281), PEAP

• Inner Authentication: MSCHAPv2 (RFC 2759)

Belnet - Workshop govroam 31/03/2016

Page 19: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Protocols & Methods

EAP Encapsulation "How EAP can be

transported"

– In order to transport EAP messages, they must be encapsulated

– Between client and SP (802.1x)

• EAP over LAN = “EAPOL”

– Between Sp & IdP, IdP & IdP

• RADIUS

Belnet - Workshop govroam 31/03/2016

Page 20: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Security

Outer authentication

– Goal : securely transport the EAP messages between peers

– Authenticate the server (to avoid MitM attacks)

– PEAP, EAP-TTLS

Inner authentication

– Transmit unique user attributes (credentials)

– via MSCHAPv2

Belnet - Workshop govroam 31/03/2016

Page 21: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Protocols & Methods

Belnet - Workshop govroam 31/03/2016

Page 22: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Security EAP, 802.1X and RADIUS must be secured

Belnet - Workshop govroam 31/03/2016

Service Provider

Institution-A.be

[email protected]

Identity Provider

Institution-A.be

Client

Page 23: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Security EAP, 802.1X and RADIUS must be secured

Choice of security mechanisms is important

Belnet - Workshop govroam 31/03/2016

Service Provider

Institution-A.be

[email protected]

Identity Provider

Institution-A.be

Client

Page 24: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (1/11)

1 The User contacts the Service Provider (SP)

(Wireless Access Point) of institution A (SSID = govroam)

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

Page 25: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (2/11)

2 SP of institution A asks the user's identity.

Not yet the credentials!

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

2

Page 26: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (3/11)

3

User identity is transmitted to Identity

Provider (IdP) (RADIUS server)

of institution A

using EAP Access-Request message

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

2

Page 27: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (4/11)

4 Based on the identity the IdP

of the institution A knows that user doesn't belong to its own user database and will transmit

the Access-Request to the Belgian RADIUS server.

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

2

Page 28: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (5/11)

[email protected]

5 Based on the realm part of the identity the

Belgian RADIUS server transmits the Access-Request

to the RADIUS server of institution B

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

2

Page 29: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (6a/11)

6a Now the IdP of institution B

knows the User and a TLS tunnel is established between User and RADIUS server using

EAP encapsulation mechanism (outer authentication)

6

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

2

Page 30: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (6b/11)

6b The User checks during TLS establishment

the RADIUS server certificate of his institution.

6

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

2

Page 31: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (7/11)

7 Now the User is authenticated against its own institute's IdP, using traditional mechanisms

(challenges, certificates, token...) (Inner authentication)

6 7

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

2

Page 32: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (8/11)

[email protected]

8 If the User is correctly authenticated, the RADIUS server of institution B

sends an Access-Accept to the Belgian RADIUS server,

otherwise it sends an Access-Reject

6 7

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

2

Page 33: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (9/11)

9 Belgian RADIUS server sends the

Access-Accept to institution A

6 7

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

[email protected]

Belgian

Top-Level

Radius

2

9

Page 34: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (10/11)

10 The IdP of institution A tells

his SP to grant access to the User and provide all information

related to the local access policy ( vlan, IP address, ...)

6 7

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

[email protected]

10

2

9

Page 35: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Authentication Flow

Belnet - Workshop govroam 31/03/2016

National Level (11/11)

[email protected]

11 User can now access

LAN and Internet

6 7

Service Provider

Identity Provider

Institution-A.be

Institution-A.be

Identity Provider

Institution-B.be

Belgian

Top-Level

Radius

10

2

9

Page 36: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

How to implement

Page 37: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

42

Prerequisites (out of scope)

Wi-Fi access point that must:

– be IEEE 802.1X compliant

– broadcast the SSID "eduroam" or “govroam” (govroamtest for

this session)

– offer IEEE 802.11b or better

– implement WPA/TKIP or better (Belnet strongly recommends

WPA2-AES!)

– Allow traffic on defined ports (please refer to govroam)

User database:

– LDAP

– Active Directory

31/03/2016 Belnet - Workshop govroam

Page 38: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

43

Prerequisites (out of scope)

Server certificates

– Don't use a self-signed server certificate

– Successfully import server & chain certificate into Windows

– Use dcs.belnet.be to get a signed server certificate

Correct server time

– Important for the setup of TLS-tunnels

– Use Belnet's NTP server time.belnet.be to get the correct time

Firewalls & Ports

– UDP 1812

– UDP 1813

31/03/2016 Belnet - Workshop govroam

Page 39: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Radiator Installation

Why “Radiator”?

– Belnet uses this product

– Easy & straightforward to deploy on Linux, Windows, ...

– Broad support for Identity & Access Management backends

– One of the first solutions which supported RadSec

31/03/2016 Belnet - Workshop govroam

Page 40: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Freeradius Installation

Why “Freeradius”?

– Free

– Easy to deploy on Linux, Windows, ...

– Broad support for Identity & Access Management backends

– Now supports RadSec

31/03/2016 Belnet - Workshop govroam

Page 41: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

W2012 R2 with NPS

Why “NPS”?

– Best option in windows environment

– Easy to deploy on Windows, ...

– Easy link to AD

31/03/2016 Belnet - Workshop govroam

Page 42: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

W2012 R2 with NPS

Server set-up:

– Windows 2012 server R2 with NPS

– Valid server certificate

31/03/2016 Belnet - Workshop govroam

Page 43: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Hierarchy

31/03/2016 Belnet - Workshop govroam

AS

belnet.be

AS

ta.belnet.be

Belgian Top-Level AS

“Federation”

“Institution”

Page 44: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

51

Components overview

WAP + CTRL

31/03/2016 Belnet - Workshop govroam

RADIUS (Windows NPS) Identity server (AD)

Belnet Radius

Page 45: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Radius server installation

31/03/2016 Belnet - Workshop govroam

RADIUS (Windows NPS) Identity server (AD)

WAP + CTRL

Belnet Radius

Page 46: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Radius server installation: Configuring RADIUS client (wlan controller)

31/03/2016 Belnet - Workshop govroam

WAP + CTRL

RADIUS LDAP/AD

Belnet Radius

Page 47: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Radius server installation: Configuring the remote RADIUS

31/03/2016 Belnet - Workshop govroam

WAP + CTRL

RADIUS LDAP/AD

Belnet Radius

Page 48: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

W2012 R2 with NPS

Server set-up:

31/03/2016 Belnet - Workshop govroam

Page 49: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Radius server installation: Configuring proxy RADIUS

31/03/2016 Belnet - Workshop govroam

WAP + CTRL

RADIUS LDAP/AD

Belnet Radius

Page 50: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

W2012 R2 with NPS

Server set-up:

31/03/2016 Belnet - Workshop govroam

Page 51: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Radius server installation: Link with LDAP

31/03/2016 Belnet - Workshop govroam

WAP + CTRL

RADIUS LDAP/AD

Belnet Radius

Page 52: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

W2012 R2 with NPS

Server set-up:

31/03/2016 Belnet - Workshop govroam

Page 53: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

W2012 R2 with NPS

Server set-up:

31/03/2016 Belnet - Workshop govroam

Page 54: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

61

Radius server installation: Configuring top level RADIUS

31/03/2016 Belnet - Workshop govroam

WAP + CTRL

RADIUS LDAP/AD

Belnet Radius

Page 55: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

62

Registration @ Belnet

31/03/2016 Belnet - Workshop govroam

govroam web-interface

– Facilitate the configuration of your govroam parameters

• RADIUS servers

• Shared secrets

• Test accounts

Page 56: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Demo

Page 57: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Demo Environment

Use case:

– Internal wifi users in a specific VLAN (21)

– External wifi users in a separate VLAN (666)

We will generate/analyse 3 flows:

– A home user login locally (flow 1)

– An external user login locally (flow 2)

– A home user login from another organization (flow 3)

Belnet - Workshop govroam 31/03/2016

Page 58: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

67

Demo environement: Network design

31/03/2016 Belnet - Workshop govroam

Page 59: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

68

Authentication Flow 1 local - local

A user from local institution ta.belnet.be will send access request

to local “govroamtest” WLAN

VLAN access depends on USER login

Ta.belnet.be NPS + AD

Belgian Top-Level Radius

[email protected]

wlan-ctrl

SSID = “govroamtest”

roaming1.belnet.be roaming2.belnet.be

31/03/2016 Belnet - Workshop govroam

Page 60: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

69

Authentication Flow 2 remote - local

A remote user from Belnet will send access request

to local “govroamtest” WLAN

ta.belnet.be Radius

Belgian Top-Level Radius

[email protected]

wlan-ctrl

SSID = “govroamtest”

radius.belnet.be ldap.belnet.be

31/03/2016 Belnet - Workshop govroam

roaming1.belnet.be roaming2.belnet.be

Page 61: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

70

Authentication Flow 3 local - remote

A local user from institution ta.belnet.be will send access request

to remote Belnet's “govroam” WLAN

Ta.belnet.be RADIUS + LDAP

Belgian Top-Level Radius

[email protected]

wlan-ctrl

SSID = “govroam”

Ldap belnet.be

roaming1.belnet.be roaming2.belnet.be

31/03/2016 Belnet - Workshop govroam

Page 62: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Conclusion

Page 63: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Conclusion

Technical Framework

Demo

Belnet is there to help you

Q&A

Belnet - Workshop govroam 31/03/2016

Page 64: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

What do you think?

Page 65: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Final roundtable

Are you ready to join?

What would you need more to start?

Belnet - Workshop govroam 31/03/2016

Page 66: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Thank you

Page 67: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Use case

Page 68: Workshop roaming services: eduroam / govroam · Authentication Flow 1 local - local A user from local institution ta.belnet.be will send access request to local “govroamtest”

Use case

To be added