Eduroam support broken

Since the update to I cannot connect to the eduroam WLAN. Previously it was configured with the Roamer app and worked flawlessly. See configuration details:

  • Network name (SSID) eduroam
  • Security WPA2 Enterprise
  • Authentication EAP-TTLS
  • Encryption AES
  • Root-CA-Certificatie Deutsche Telekom Root CA 2 Authentication
  • Server radius.uni-ulm.de
  • Inner Authentication PAP
  • Outer identity anonymous@uni-ulm.de
  • Inner identity max.muster@uni-ulm.de (individual kiz-Email)
I cannot confirm that. For me, eduroam works in as it did before...

lpr ( 2017-07-27 12:02:08 +0200 )edit

I can confirm that the update broke the eduroam support also for me.

Alex ( 2017-07-28 09:41:45 +0200 )edit

Ok I got it solved for me:

  1. renamed my eduroam config
  2. deactivated the eduroam network in setting > wlan (by tapping on the eduroam network)
  3. Searched for the eduroam network and tried to connect to the network (which was unsuccessful). Then deactivated wlan.
  4. Then I renamed my eduroam config again, activated the WLAN, activated the eduroam network and it was finally able to connect to the network again

Earlier I also changed the config file permissions to -rwx------ - but this didn't solve the issue and I tried the things mentioned above.

Alex ( 2017-07-28 10:19:33 +0200 )edit

In which state is your WLAN before step 1?

carolus ( 2017-07-28 10:48:50 +0200 )edit

@carolus IIRC it was deactivated. :)

BTW my university is using EAP-TLS MSCHAPv2 eduroam (with user certificates).

Alex ( 2017-07-28 10:53:57 +0200 )edit

answered 2017-07-27 12:10:42 +0200

rincewind gravatar image

I had to edit the wifi config file (e.g. add a comment) to change the modification timestamp of the file. Then connman automatically rereads the config and eduroam worked again. After that also my identity was correctly displayed in settings->wifi->myeduroamconnection. Before the edit it was empty.

Which type of WPA-Enterprise does your Eduroam use: also EAP-TTLS and PAP?

carolus ( 2017-07-27 13:39:45 +0200 )edit

No, I use EAP-PEAP and MSCHAPv2. But I don't think that's the problem here. Have you tried to delete the old config and create the config again?

And as a wild guess, are you sure radius.uni-ulm.de still uses a certificate with Root-CA "Deutsche Telekom Root CA 2"? The DFN-PKI is in transition to the new Root-CA "T-TeleSec GlobalRoot Class 2", all new certificates will use this one these days.

rincewind ( 2017-07-27 15:06:23 +0200 )edit

I deleted the old config by the Roamer app and created manually the config file like in the eduroam thread]. I also tried the GUI in the network settings.

carolus ( 2017-07-27 15:22:55 +0200 )edit

answered 2017-10-11 10:43:02 +0200

Alex gravatar image

I just tried to fix my eduroam wifi on my tablet with the steps I posted in the comments earlier and this indeed does not work. There is missing one step to make it work.

So I fixed my eduroam wifi with the following steps:

  1. Deactivate WIFI
  2. Change the config file name from wifi_eduroam.config to wifi_eduroam.config.tmp
  3. Activate WIFI so that connman sees that there is no eduroam config anymore and removes this accesspoint/service
  4. Deactivate WIFI again
  5. Create the new file wifi_eduroam.config as root user (devel-su), put all the content from wifi_eduroam.config.tmp into this file and remove the old wifi_eduroam.config.tmp file (optionally also change the permissions so that nemo user is not able to read your file)
  6. Activate WIFI again
  7. Now long press the eduroam network and select "forget network"
  8. Deactivate and activate your WIFI again
  9. Now the eduroam network reappears. Activate the eduroam network by tapping on it => It automatically connects to the eduroam wifi now

Could somone please first try the following and report if it is possible to break down the steps above to the following?:

  1. Go to 'Settings > Wifi'
  2. Long press on the eduroam network and select 'forget network'
  3. Restart your Wifi by deactivating and reactivating it
  4. Now connman re-reads the existing eduroam configuration file and the eduroam network reappears in the Wifi list. Now activate the eduroam network by tapping on it and it should connect to your enterprise wifi
I have still no eduraom. In dmesg I see messages from wlan module, that my phone got a deauth frame with reason 23 (IEEE 802.1X authentication failed)

Build: Hardware Version: My eduroam settings: EAP: ttls Phase2: PAP

ckaktus ( 2017-10-11 14:04:55 +0200 )edit

answered 2017-09-07 17:58:42 +0200

googl1 gravatar image

For me this broke with at UPF Barcelona.

None of the above helped.

