Skip to main content

Simple Roaming Certificate

This package contains the functions for creating all the certificates, keys etc. for Govroam, or eduroam. The certificates are specifically designed to work well with eduroam/Govroam and include all the features required to ensure that as many clients as possible are compatible.

It's based heavily on the python cryptography module.

Usage

from simple_roaming_certificate import gencerts

csrsubject, cacert, cakey_enc, csrkey_enc, servercert, crlcert = gencerts(c,st,l,o,ou,cn,crldp,passphrase,bits)

The following certificate are available for generation:

RootCA

To be installed on the client, as a trusted Root Certificate. If using the CAT, upload this when creating a profile and set the "Name (CN) of Authentication Server" to idp.westeros.zz. It can be pushed out to clients via a policy, or downloaded in 'mobileconfig' files or published on a web site

Server Cert

To be installed on the RADIUS IdP. Put this, along with the Server Key below, on to your RADIUS server and configure as part of the EAP security. Do not install the above Root CA on the server.

Server Key

To be installed on the RADIUS IdP, as above.

CRL

Publish at the URL https://<cn>/list.crl. It should be accessible by all clients. Whilst not necessary for clients to authenticate it reduces the risk of some clients rejecting the authentication.

RootCA Key

To be kept safe, along with the password used, and is required for any future server certificates, or to change the CRL

Notes

You can check the certificates by running:

openssl x509 -noout -text -in <certname>

which will work for rootca.pem and server-cert.pem

openssl rsa -in <keyname> -check

which will work for server-key.pem and root-key.pem

openssl crl -noout -text -in <crlfile>

which will work for list.crl

Metadata

Release files for simple-roaming-certificate 1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for simple-roaming-certificate 1.3
File Size Uploaded
simple-roaming-certificate-1.3.tar.gz 3.5 kB Details

Release files / simple-roaming-certificate-1.3.tar.gz

Download URL simple-roaming-certificate-1.3.tar.gz
Size 3.5 kB
Tags Source
SHA-256 checksum
How to use checksums
2b279598f878d92f65363a1bed6f3b262bcee2369333bb836e34ffe293f9385b
BLAKE2b-256 checksum
How to use checksums
387cb6ad81342ea7186d5fab5b803c564ccfa559be89dfff4625ddda3513b651
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.13.0 pkginfo/1.5.0.1 requests/2.19.1 setuptools/40.4.3 requests-toolbelt/0.8.0 tqdm/4.33.0 CPython/2.7.5

Release history Release notifications | RSS feed

This release

1.3 This release

1 release file

1.2

1 release file

1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page