Eduroam wireless network - Windows 7 How to configure laptop computers and tablets to connect to the eduroam wireless network. Contents Introduction 1 Instructions for Windows 7 Devices 2 Technical Information 6 Introduction UCA offers wireless network access across all campuses for staff and students using their own or loan laptops and tablets. A good wireless signal is available in all libraries and in some other areas. The name of the network is Eduroam. It is not an open wireless network: a user name and password must be supplied. The instructions below tell you how to connect. Please follow the instructions carefully. In all cases the instructions are for the most recent version of the operating system. If you have an older version, you are encouraged to update it. Some operating systems require that you download the root certificate for the ucreative certification authority: Root certificate for the ucreative certification authority - x509 DER encoded Wireless network access is subject to the same acceptable use policies as wired network access. It is also restricted. You will be able to access the internet wirelessly for web browsing, FTP download, imap and pop mailbox access, instant messaging, and most other internet applications. You will not be able to access network fileshares or other local resources wirelessly, such as printing. Which platforms are supported? Laptops running Microsoft Windows XP Laptops running Microsoft Vista Laptops running Microsoft Windows 7 Laptops / Tablets running Windows 8 Laptops running Mac OSX 10.4 (Tiger) Laptops running Mac OSX 10.5 (Leopard) Laptops running Mac OSX 10.6 (Snow Leopard) Laptops running Mac OSX 10.8 (Mountain Lion) S60 Symbian mobile phones equipped with wireless wifi, such as some of the Nokia E- and N- series Apple ios 4 and above Android 4.2 (Jellybean) IT SERVICES 1
1. From the Start menu, select Control Panel. The Control Panel opens. 2. Select Network and Internet, then select the Network and Sharing Center. 3. Select Manage wireless networks. 4. Click on Add. 5. Select Manually create a network profile. 2 IT SERVICES
6. Ensure the settings on this window are as per the example : Network name = eduroam Security type = WPA-Enterprise Encryption type = TKIP Tick the Start this connection automatically box. Click on Next: 7. Click on the Change connection settings box. 8. In the eduroam Wireless Network Properties window, click on the Security tab: 9. Click on the Settings button. IT SERVICES 3
10. Ensure that all check boxes on this dialogue box are unticked, then click on Configure. 11. In this window deselect to Automatically use my windows logon name and password (and domain if any) otherwise you will not be able to connect to eduroam. Click OK. 12. You are then returned to the Properties window. Click on Advanced settings. 4 IT SERVICES
13. Ensure : Specify authentication modes is ticked. User authentication is visible. Enable single sign on for this network is unticked. Click on Save credentials. Click OK. 14. Type your ucreative login. Your ucreative login is the username you use to log in to University computers. It is the same as the first part of your University email address and usually consists of one of your initials, followed by your family name, sometimes followed by a number. In the Password field type the password for your ucreative login. Click on OK. 15. Close any open windows - your machine should be connected to eduroam. Access the Internet in the usual way. IT SERVICES 5
Technical Information The following technical information is to help people running Linux or other operating systems to configure their laptops. The system used to authenticate users and encrypt network traffic on eduroam at ucreative is WPA Enterprise, Wi-Fi Protected Access Enterprise. Other forms of WPA, including WPA-PSK and WPA2- Enterprise are not supported and will not work. WPA Enterprise is a combination of 802.1x network access control and wireless encryption techniques. Both AES and TKIP encryption techniques are supported. 802.1x relies on EAP, the Extensible Authentication Protocol to authenticate users. PEAPv0/EAP-MSCHAPv2 is used to transmit the ucreative login and password in a secure manner to Active Directory servers for verification. However, in order for laptops to be able to work consistently across eduroam sites, the ucreative login must be provided with @ucreative. ac.uk appended. PEAPv0/EAP-MSCHAPv2 requires that the server doing the authentication identify itself by means of an X.509 electronic certificate in a similar manner to a secure website. The certificate supplied by the ucreative authentication server is signed by the ucreative certification authority. This certification authority will be unknown to all computers except those issued by ucreative IT. Therefore for most operating systems either verification of the certificate must be turned off or the certificate manually installed and trusted. The root certificate for the ucreative certification authority can be downloaded onto computers on the internal wired network from here: http://ul03vn0006/certsrv/ Fast Reconnect is not supported and should be disabled. The ucreative implementation of eduroam also supports authentication using EAP-TLS. This method requires that the laptop has a certificate installed, and is only for laptops and other devices supplied by ucreative IT. EAP-TLS will not work with other laptops. Access for visitors to the University for the Creative Arts The Eduroam network allows allows students and staff from other academic institutions to gain network access here at UCA and it permits UCA students and staff to access the network at other some academic institutions. The University implements JANET Roaming Service Tier 2 (documented at: http://www. ja.net/services/authentication-and-authorisation/janet-roaming.html), this allows visitors from participating organisations to access the Eduroam network here using their own username and password. Visitors should ensure that their eduroam setup is working correctly in their own organisation before travelling. Access for University for the Creative Arts users visiting other institutions Not all academic institutions support Eduroam, JANET provide an up to date list. Students should ensure that their Eduroam setup is working correctly here before travelling. They can then log in at other Eduroam enabled institutions using their ucreative login and password. It is important that their Eduroam setup uses the username in the format give in this document, with ucreative.ac.uk either as part of the username or as the realm. Whilst some other formats will work within the UCA campus, only this format can be successfully routed by other institutions back to the University s servers for checking 6 IT SERVICES