Wednesday 9 June 2010

Configuring Eduroam on the N900

Getting Eduroam to run on your N900 may involve a lot of fiddling, but at least, it's possible with the new PR1.2 firmware. I had to do the following in order to be able to use my LRZ/MyTUM account for Eduroam; but bear in mind that configuration may vary for other academic institutions! (For example, my institutions gives me login and password, whereas other institutions hand out login and an individual certificate.)
  1. Install the newest firmware (PR1.2 at the time of this writing).
  2. From the N900's Web browser, download the root certificate of the DFN and install it in the N900's certificate manager. Make sure that you allow the certificate to be used for WLAN authentication (you may also tick the other options if you wish).
  3. You now may try to get Eduroam to run. If you're lucky and your institution doesn't require support for PAP with TTLS, you're done. Chances are, however, that it doesn't. Curse and do a lot of googling. Come across the forum page http://talk.maemo.org/showthread.php?t=39399&page=2
  4. From the N900's Web browser, download the little software program wlan_tool which was written by a Nokia employee. (For background information why you need it, see the corresponding forum entries.) Throw your inhibitions concerning downloading software from some forum overboard and pray that this software was really developed by an honest Nokia employee and really doesn't open any backdoors or the like. Save the application file (a .deb file) to a folder where you will find it again.
  5. Open the file browser, navigate to that download folder, and open the wlan_tool_blabla.deb software package file. The program manager will open and install the file (after you clicked on "yes, I know that I'm a silly person because I'm about to install unofficial software because Nokia messed things up.")
  6. You now have a new program installed called WLAN Tool. Run this software by clicking on it in the application list/menu. Due to its name beginning with the letter W, it probably will appear near the very end of the application list.
  7. The software opens a new window. In General settings, tick the option Allow TTLS/PAP. Leave the other things as-is; they don't have anything to do with authentication.
  8. Close the WLAN tool application.
  9. Reboot the N900.
  10. Open the Settings program, open the Internet connections, create a new connection with the following parameters (N.B. these are spread out over several screens):
    • Connection name: eduroam (or whatever you prefer)
    • SSID: eduroam
    • Mode: Infrastructure
    • Security method: WPA with EAP
    • EAP type: TTLS
    • Choose certificate: none
    • EAP method: EAP PAP (if you haven't rebooted after you installed the WLAN tool, you won't be offered to select EAP PAP here)
    • User name and password as provided by your institution, e.g., lars.zbigniew.delorenzo@mytum.de and *******
    • Before you click the done button, click extended first! A new pop-up will open. Here, navigate to the EAP tab, tick Use manual user name: yes, and enter the "anonymous" user name which is the default for your academic institution (in my case: anonymous@mwn.de). Click Save.
    • Save everything and enjoy. Note that it sometimes may take rather long (many seconds) to log into the Eduroam network.



Nachtrag für MWN-Nutzer (Juli 2010)


(This is only relevant to people in Munich/München who work or study at TUM and perhaps LMU, FH/HS, etc., so I post it in German.)


Nachdem ich all diesen Mist für EAP PAP gemacht habe, habe ich erfahren, dass das MWN durchaus andere Authentifizierungsmethoden neben EAP PAP anbietet – allerdings fuktionieren die nicht mit einer selbstgewählten ...@mytum.de-Adresse, sondern ausschließlich mit dieser kryptischen, vom LRZ vorgegebenen Adresse. Falls man die nicht kennt (Achtung, das war bei mir nicht dasselbe wie diese ellenlange Mytum-ID, die ich bei meiner Einstellung auf einem Zettel genannt bekommen habe), kann man sich einfach bei Mytum einloggen und sich in bei den Konto- oder Maileinstellungen diese LRZ-Kennung anzeigen lassen. Ich hatte es stattdessen mit meiner Mytum-Kennung versucht, und genau das geht idiotischerweise dann nur mit EAP PAP.

1 comment:

  1. Great thx a lot ! Your approach is the only one that actually works for me, it seems that the configurations for Eduroam vary from place to place ...

    ReplyDelete