IT-Service: Eduroam

Quickinformation

Allows all GSI users with a valid weblogin account to log in to a Wifi access point with the SSID eduroam and use Wifi.

  • Target group: All Employees with a valid Weblogin-Account (@gsi.de or @fair-center.eu)

Service Description

Openroaming worldwide...

Eduroam is a worldwide association of facilities and institutes in the research and education sector. This network enables members of other universities and research institutions to access the Internet with their home account. Eduroam is also often available on public hotspots. BayernWLAN is an example for a public hotspot cooperating with eduroam. 

GSI Darmstadt is participating over Deutsche Forschungsnetz (DFN) with eduroam.

Configuration guides

Note: Due to the different operating systems (Windows, Linux, Android, iOS) in different versions, not all cases can be covered and supported. If you ultimately have to resort to manual configuration, you must also configure the root CA. Without this, you can easily fall victim to identity theft.

Windows

Central managed Windows-Devices

  • Connect your device with the GSI-Network and logon
  • Your computer automatically receives the new Eduroam configuration via group policy (you can also trigger the process manually by entering the gpupdate command in an input window)
  • If you are asked for a user ID for authentication (e.g. during an initial installation), enter your weblogin name (e.g. m.mustermann@gsi.de) along with your weblogin password.
  • Reboot your device

Non-central managed Windows-Devices

  • Connect to the following website using a browser: https://cat.eduroam.org
  • Search for "GSI Helmholtzzentrum für Schwerionenforschung GmbH" within the list of instittutes and select it
  • Click on the field user group and select Eduroam2025
  • An executable file will be created for download.
  • Execute this file (Double click)
  • If you are asked for a user ID for authentication (e.g. during an initial installation), enter your weblogin name (e.g. m.mustermann@gsi.de) along with your weblogin password

Smartphones

----------

If the connection with eduroam fails, check the following:

  • Access data: Enter your web login credentials (without "@gsi.de". Examples: PROZ, DIO).
  • Delete a previously existing Wi-Fi profile:
    • Android:
      1. open the settings on the device.
      2. tap on Connections
      3. Tap the settings next to the Wi-Fi you are connected to and remove this Wi-Fi
    • Apple iOS:
      1. On the iPhone, open the Settings app.
      2. click on the "Wi-Fi" option there.
      3. there is a blue "i" next to the various entries. Tap on the sign next to the Wi-Fi profile that you want to delete
      4. then select "Forget this network". 
      •  You may have installed an eduroam profile using the outdated eduroamCAT app. Delete the profile as follows: Settings >> General >> VPN & Device Management. Delete the Eduroam profile here. The eduroamCAT app is no longer supported and can be deleted.

 

Linux

This will install a profil for NetworkManager or wpa_supplicant. You need Python 3.6+ for the installation.

  • Connect to the following website using a browser: https://cat.eduroam.org
  • Search for "GSI Helmholtzzentrum für Schwerionenforschung GmbH" within the list of institutes and select it
  • Click on the field user group and select Eduroam2025
  • A Python script will be created for download
  • After download open a terminal window and change to your download folder
  • execute the following command: python3 [eduroam.....py]
  • If you are asked for a user ID for authentication (e.g. during an initial installation), enter your weblogin name (e.g. m.mustermann@gsi.de) along with your weblogin password

MacOS

  • Connect to the following website using the Safari browser: https://cat.eduroam.org
  • Search for "GSI Helmholtzzentrum für Schwerionenforschung GmbH" within the list of instittutes and select it
  • Click on the field user group and select Eduroam2025
  • A configuration file will be created for download.
  • After Download the installation process will be started automatically
  • If you are asked for a user ID for authentication (e.g. during an initial installation), enter your weblogin name (e.g. m.mustermann@gsi.de) along with your weblogin password

Manual Configuration

Example shown under Linux with the network manager

  • Download the Root-CA file: Harica_TLS_RSA_RootCA2021
  • Start the network manager
    • Create a new profile with SSID eduroam
    • Configure the following parameters under the security tab
    • Security: WPA- & WPA2-Enterprise
    • Legitimation: Tunneled TLS
    • Anonymous Identity: eduroam2025@gsi.de
    • CA-Certificate: <select the downloaded Root-CA file from Harica>
    • Domain: gsi.de
    • Inner Legitimation: MSCHAPv2 (no EAP)
    • User name: <your Weblogin-Name>
    • Password: <your Weblogin-Kennwort>

Hints for the Root-CA certificatw:

  • Always configure with the root CA, otherwise identity theft can occur unnoticed

  • For Samsung phones, WLAN must be selected as the intended use for the certificate during installation

Availability and support

  • not covered by on-call duty
  • Supporttimes: Mo-Fr within core-working time
  • Support-Email: network-service

Loading...