SlideShare a Scribd company logo
Adding OpenRoaming to existing IdP
and roaming federation service
first deployment experiences
Radiator Software: Who we are?
● One of the few commercial RADIUS, RADSEC, Diameter,
TACACS+ software vendors – Radiator
● SIM authentication (with IMSI privacy), Policy&Charging and
other operator oriented extension packs for Radiator
● Small scale RADIUS, Wi-Fi Roaming as a Service service
provider (Radiator Auth.Fi, roam.fi, eduroam Finland (since
2004) etc.)
● In March 2023 it will be 25 years from the first release of
Radiator
Adding OpenRoaming to …
● roam.fi regional Wi-Fi roaming federation
service
● Radiator Auth.Fi – Enterprise Wi-Fi IdP as a
service
● The first deployment experiences
roam.fi
Regional Wi-Fi roaming service
Roam.fi – regional Wi-Fi roaming federation
● Started in 2006 as a Langaton Tampere (Wireless Tampere) Wi-Fi
community network
● Based on eduroam architecture and technology, but open for all
● Centralised RADIUS hierarchy with each organisation joining with
their own Wi-Fi network and RADIUS server
● Rebranded as roam.fi when the roaming coverage expanded
outside Tampere and neighbouring cities to Finnish cities like
Seinäjoki and Vaasa.
● Nowadays used actively especially in Tampere Region for
education, municipal work, guests, tourists, university people etc.
Radiator Auth.Fi
Enterprise Wi-Fi as a
service
Redundant roam.fi
RADIUS service in public
cloud
Roam.Fi Architecture
Tampere University
RADIUS
Other customers
connecting via
RADIUS, e.g. City of
Seinäjoki, Seinäjoki
education etc.
Default RADIUS route
for all roam.fi
members, but no own
default RADIUS route
RADIUS
RADIUS
RADIUS
RADIUS
Customers are used
to connect via
RADIUS, getting them
to use RadSec will
not happen very
quickly and easily.
One question is that should RADIUS
connections be allowed and do we need to
send Accounting for Settlement-Free
OpenRoaming.
Radiator Auth.Fi
Enterprise Wi-Fi as a
service
Redundant roam.fi
RADIUS service in public
cloud
Adding OpenRoaming to Roam.Fi
Tampere University
RADIUS
Other customers
connecting via
RADIUS, e.g. City of
Seinäjoki, Seinäjoki
education etc.
RADIUS
RADIUS
RADIUS
RADIUS
Adding OpenRoaming to Roam.Fi was as
simple as adding two more Radiator
processes and setting them as roam.fi’s
default RADIUS route for unknown realms.
Now any roam.fi member can try OpenRoaming
just by adding OpenRoaming Settlement-Free
RCOIs to their Wi-Fi network beacon
advertisement.
OpenRoaming
roaming partners
OpenRoaming
roaming partners
Next steps
● Getting the largest roam.fi organisations to try
OpenRoaming and broadcast OpenRoaming RCOIs
● Convince the organisations to take OpenRoaming into
production => make it a roam.fi production service
● Switching gradually to RadSec connections with
organisations that can deploy it
● Some minor configuration for RADIUS attributes,
certificate CRLs, 3gppnetwork.org realm
Radiator Auth.Fi
Enterprise Wi-Fi IdP as a Service
Radiator Auth.Fi
Radiator Auth.Fi is a RADIUS based Wi-Fi authentication cloud service for
authenticating network users and guests. It provides a RADIUS based user
authentication as a service mainly for Wi-Fi, but can be used also for wired
802.1X or even RADIUS based VPN authentication.
Entry requirement is a RADIUS capable Wi-Fi controller and access points –
no new hardware is needed for enterprise-level WPA2/WPA3 security for your
company Wi-Fi. Radiator Auth.Fi includes RADIUS servers, but can also be
integrated with customer RADIUS servers for additional control.
Subscription based service is delivered from the Google Cloud. Regional
service endpoints are added based on demand.
Radiator Auth.Fi is designed to work with RADIUS roaming federations such
as eduroam and govroam. Optional add-ons include client certificate
authentication and self-service guest access solution and roaming
federation integrations.
Radiator Auth.Fi for…
Employees, contractors, regular
users of organisation Wi-Fi
Organisation’s guest Wi-Fi users Roaming users
Secured WPA2/WPA3 Enterprise Wi-Fi access
Certificate provisioning and authentication
Roaming with Radiator Auth.Fi
Roaming was done bases on
the Wi-Fi network name
(SSID, e.g. roam.fi, eduroam)
OpenRoaming
Roaming with Radiator Auth.Fi
Inbound RadSec
Radiator instance
with Kyrio certificates
was added for IdP
functionality
Roam.fi federation
top-level Outbound
RadSec Radiator
instance was used for
OpenRoaming
connection
Providing a Radiator Auth.Fi
customer OpenRoaming IdP only
requires enabling it in the service and
adding NAPTR record to customer
DNS domain.
“Available now”, only minor RADIUS
attribute and Kyrio certificate CRL
and 3gppnetwork.org realm
configuration pending.
How long did it take?
● ~22.5h in work time so far for both IdP and
roaming service, but more as calendar time
● Configuration guides helped a lot and a guide is
under work for Radiator as well => next
deployment will require less work time
● Most of the calendar time was spent in waiting
for Radiator Software to get verified by Kyrio
and the delivery of certificates needed.
Thank you. Questions, Comments?
Follow Radiator Software for more information…
Radiator Software blog:
https://blog.radiatorsoftware.com/
Twitter:
https://twitter.com/RadiatorAAA
Slideshare:
https://slideshare.net/radiatorsoftware/
Bookings for conference calls:
https://radiatorsoftware.com/contact/ / info@radiatorsoftware.com
Meet us in London 7th - 9th of November 2022
Karri Huhtanen and Heikki Vatiainen will be
attending IETF 115 in London, UK on the 7th of
November, but we stay in London for additional
days to meet new, existing and interested
customers, partners and companies.
Please, contact us if you want to meet:
firstname.surname@radiatorsoftware.com
sales@radiatorsoftware.com

More Related Content

Similar to Adding OpenRoaming to existing IDP and roaming federation service

24online-Internet billing & bandwidth management solution
24online-Internet billing & bandwidth management solution24online-Internet billing & bandwidth management solution
24online-Internet billing & bandwidth management solution
Nitin Mittal
 
Maximizing SD-WAN Architecture with Service Chaining - VeloCloud
Maximizing SD-WAN Architecture with Service Chaining - VeloCloudMaximizing SD-WAN Architecture with Service Chaining - VeloCloud
Maximizing SD-WAN Architecture with Service Chaining - VeloCloud
VeloCloud Networks, Inc.
 
Secure Your Network for Scale & the Cloud
Secure Your Network for Scale & the CloudSecure Your Network for Scale & the Cloud
Secure Your Network for Scale & the Cloud
VeloCloud Networks, Inc.
 
Getting Started with ThousandEyes
Getting Started with ThousandEyesGetting Started with ThousandEyes
Getting Started with ThousandEyes
ThousandEyes
 
Rebaca DPI and PCRF Expertie Overview
Rebaca DPI and PCRF Expertie OverviewRebaca DPI and PCRF Expertie Overview
Rebaca DPI and PCRF Expertie Overview
Arshad Mahmood
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Amazon Web Services
 
Veddio Overview
Veddio OverviewVeddio Overview
Veddio Overview
gregbugay
 
OpenRoaming- A Global Wi-Fi Roaming Enabler
OpenRoaming- A Global Wi-Fi Roaming EnablerOpenRoaming- A Global Wi-Fi Roaming Enabler
OpenRoaming- A Global Wi-Fi Roaming Enabler
Hughes Systique Corporation
 
Radius Protocol
Radius ProtocolRadius Protocol
Radius Protocol
Netwax Lab
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivity
MarketingArrowECS_CZ
 
Acit Mumbai - understanding vpns
Acit Mumbai - understanding vpnsAcit Mumbai - understanding vpns
Acit Mumbai - understanding vpns
Sleek International
 
12 Understanding V P Ns
12  Understanding  V P Ns12  Understanding  V P Ns
12 Understanding V P Ns
AamirAziz
 
SD-WAN - comSpark 2019
SD-WAN - comSpark 2019SD-WAN - comSpark 2019
SD-WAN - comSpark 2019
Advanced Technology Consulting (ATC)
 
Jamcracker
JamcrackerJamcracker
Jamcracker
Steve Crawford
 
Via Solutions, Transforming Networks, Unlocking Potential
Via Solutions, Transforming Networks, Unlocking PotentialVia Solutions, Transforming Networks, Unlocking Potential
Via Solutions, Transforming Networks, Unlocking Potential
Small Cell Forum
 
OpenID Foundation Workshop at EIC2017
OpenID Foundation Workshop at EIC2017OpenID Foundation Workshop at EIC2017
OpenID Foundation Workshop at EIC2017
Bjorn Hjelm
 
Aryaka Bringing SASE to Life with a Zero Trust WAN.pdf
Aryaka Bringing SASE to Life with a Zero Trust WAN.pdfAryaka Bringing SASE to Life with a Zero Trust WAN.pdf
Aryaka Bringing SASE to Life with a Zero Trust WAN.pdf
KlausSchwegler
 
Using a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business networkUsing a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business network
Netpluz Asia Pte Ltd
 
Unravelling Managed SD-WAN Services
Unravelling Managed SD-WAN ServicesUnravelling Managed SD-WAN Services
Unravelling Managed SD-WAN Services
Ralph Santitoro
 
Colubris Basic Customer Presentation
Colubris Basic Customer PresentationColubris Basic Customer Presentation
Colubris Basic Customer Presentation
daten
 

Similar to Adding OpenRoaming to existing IDP and roaming federation service (20)

24online-Internet billing & bandwidth management solution
24online-Internet billing & bandwidth management solution24online-Internet billing & bandwidth management solution
24online-Internet billing & bandwidth management solution
 
Maximizing SD-WAN Architecture with Service Chaining - VeloCloud
Maximizing SD-WAN Architecture with Service Chaining - VeloCloudMaximizing SD-WAN Architecture with Service Chaining - VeloCloud
Maximizing SD-WAN Architecture with Service Chaining - VeloCloud
 
Secure Your Network for Scale & the Cloud
Secure Your Network for Scale & the CloudSecure Your Network for Scale & the Cloud
Secure Your Network for Scale & the Cloud
 
Getting Started with ThousandEyes
Getting Started with ThousandEyesGetting Started with ThousandEyes
Getting Started with ThousandEyes
 
Rebaca DPI and PCRF Expertie Overview
Rebaca DPI and PCRF Expertie OverviewRebaca DPI and PCRF Expertie Overview
Rebaca DPI and PCRF Expertie Overview
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
 
Veddio Overview
Veddio OverviewVeddio Overview
Veddio Overview
 
OpenRoaming- A Global Wi-Fi Roaming Enabler
OpenRoaming- A Global Wi-Fi Roaming EnablerOpenRoaming- A Global Wi-Fi Roaming Enabler
OpenRoaming- A Global Wi-Fi Roaming Enabler
 
Radius Protocol
Radius ProtocolRadius Protocol
Radius Protocol
 
Inteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivityInteligentní řízení WAN konektivity
Inteligentní řízení WAN konektivity
 
Acit Mumbai - understanding vpns
Acit Mumbai - understanding vpnsAcit Mumbai - understanding vpns
Acit Mumbai - understanding vpns
 
12 Understanding V P Ns
12  Understanding  V P Ns12  Understanding  V P Ns
12 Understanding V P Ns
 
SD-WAN - comSpark 2019
SD-WAN - comSpark 2019SD-WAN - comSpark 2019
SD-WAN - comSpark 2019
 
Jamcracker
JamcrackerJamcracker
Jamcracker
 
Via Solutions, Transforming Networks, Unlocking Potential
Via Solutions, Transforming Networks, Unlocking PotentialVia Solutions, Transforming Networks, Unlocking Potential
Via Solutions, Transforming Networks, Unlocking Potential
 
OpenID Foundation Workshop at EIC2017
OpenID Foundation Workshop at EIC2017OpenID Foundation Workshop at EIC2017
OpenID Foundation Workshop at EIC2017
 
Aryaka Bringing SASE to Life with a Zero Trust WAN.pdf
Aryaka Bringing SASE to Life with a Zero Trust WAN.pdfAryaka Bringing SASE to Life with a Zero Trust WAN.pdf
Aryaka Bringing SASE to Life with a Zero Trust WAN.pdf
 
Using a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business networkUsing a secured, cloud-delivered SD-WAN to transform your business network
Using a secured, cloud-delivered SD-WAN to transform your business network
 
Unravelling Managed SD-WAN Services
Unravelling Managed SD-WAN ServicesUnravelling Managed SD-WAN Services
Unravelling Managed SD-WAN Services
 
Colubris Basic Customer Presentation
Colubris Basic Customer PresentationColubris Basic Customer Presentation
Colubris Basic Customer Presentation
 

Recently uploaded

Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying AheadDigital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Wask
 
WeTestAthens: Postman's AI & Automation Techniques
WeTestAthens: Postman's AI & Automation TechniquesWeTestAthens: Postman's AI & Automation Techniques
WeTestAthens: Postman's AI & Automation Techniques
Postman
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
Building Production Ready Search Pipelines with Spark and Milvus
Building Production Ready Search Pipelines with Spark and MilvusBuilding Production Ready Search Pipelines with Spark and Milvus
Building Production Ready Search Pipelines with Spark and Milvus
Zilliz
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
Edge AI and Vision Alliance
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
Matthew Sinclair
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Safe Software
 
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptxOcean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
SitimaJohn
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
David Brossard
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing InstancesEnergy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Alpen-Adria-Universität
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
Zilliz
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
Tatiana Kojar
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
ssuserfac0301
 

Recently uploaded (20)

Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Digital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying AheadDigital Marketing Trends in 2024 | Guide for Staying Ahead
Digital Marketing Trends in 2024 | Guide for Staying Ahead
 
WeTestAthens: Postman's AI & Automation Techniques
WeTestAthens: Postman's AI & Automation TechniquesWeTestAthens: Postman's AI & Automation Techniques
WeTestAthens: Postman's AI & Automation Techniques
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
Building Production Ready Search Pipelines with Spark and Milvus
Building Production Ready Search Pipelines with Spark and MilvusBuilding Production Ready Search Pipelines with Spark and Milvus
Building Production Ready Search Pipelines with Spark and Milvus
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
 
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptxOcean lotus Threat actors project by John Sitima 2024 (1).pptx
Ocean lotus Threat actors project by John Sitima 2024 (1).pptx
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
OpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - AuthorizationOpenID AuthZEN Interop Read Out - Authorization
OpenID AuthZEN Interop Read Out - Authorization
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing InstancesEnergy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
 

Adding OpenRoaming to existing IDP and roaming federation service

  • 1. Adding OpenRoaming to existing IdP and roaming federation service first deployment experiences
  • 2. Radiator Software: Who we are? ● One of the few commercial RADIUS, RADSEC, Diameter, TACACS+ software vendors – Radiator ● SIM authentication (with IMSI privacy), Policy&Charging and other operator oriented extension packs for Radiator ● Small scale RADIUS, Wi-Fi Roaming as a Service service provider (Radiator Auth.Fi, roam.fi, eduroam Finland (since 2004) etc.) ● In March 2023 it will be 25 years from the first release of Radiator
  • 3. Adding OpenRoaming to … ● roam.fi regional Wi-Fi roaming federation service ● Radiator Auth.Fi – Enterprise Wi-Fi IdP as a service ● The first deployment experiences
  • 5. Roam.fi – regional Wi-Fi roaming federation ● Started in 2006 as a Langaton Tampere (Wireless Tampere) Wi-Fi community network ● Based on eduroam architecture and technology, but open for all ● Centralised RADIUS hierarchy with each organisation joining with their own Wi-Fi network and RADIUS server ● Rebranded as roam.fi when the roaming coverage expanded outside Tampere and neighbouring cities to Finnish cities like Seinäjoki and Vaasa. ● Nowadays used actively especially in Tampere Region for education, municipal work, guests, tourists, university people etc.
  • 6. Radiator Auth.Fi Enterprise Wi-Fi as a service Redundant roam.fi RADIUS service in public cloud Roam.Fi Architecture Tampere University RADIUS Other customers connecting via RADIUS, e.g. City of Seinäjoki, Seinäjoki education etc. Default RADIUS route for all roam.fi members, but no own default RADIUS route RADIUS RADIUS RADIUS RADIUS Customers are used to connect via RADIUS, getting them to use RadSec will not happen very quickly and easily. One question is that should RADIUS connections be allowed and do we need to send Accounting for Settlement-Free OpenRoaming.
  • 7. Radiator Auth.Fi Enterprise Wi-Fi as a service Redundant roam.fi RADIUS service in public cloud Adding OpenRoaming to Roam.Fi Tampere University RADIUS Other customers connecting via RADIUS, e.g. City of Seinäjoki, Seinäjoki education etc. RADIUS RADIUS RADIUS RADIUS Adding OpenRoaming to Roam.Fi was as simple as adding two more Radiator processes and setting them as roam.fi’s default RADIUS route for unknown realms. Now any roam.fi member can try OpenRoaming just by adding OpenRoaming Settlement-Free RCOIs to their Wi-Fi network beacon advertisement. OpenRoaming roaming partners OpenRoaming roaming partners
  • 8. Next steps ● Getting the largest roam.fi organisations to try OpenRoaming and broadcast OpenRoaming RCOIs ● Convince the organisations to take OpenRoaming into production => make it a roam.fi production service ● Switching gradually to RadSec connections with organisations that can deploy it ● Some minor configuration for RADIUS attributes, certificate CRLs, 3gppnetwork.org realm
  • 10. Radiator Auth.Fi Radiator Auth.Fi is a RADIUS based Wi-Fi authentication cloud service for authenticating network users and guests. It provides a RADIUS based user authentication as a service mainly for Wi-Fi, but can be used also for wired 802.1X or even RADIUS based VPN authentication. Entry requirement is a RADIUS capable Wi-Fi controller and access points – no new hardware is needed for enterprise-level WPA2/WPA3 security for your company Wi-Fi. Radiator Auth.Fi includes RADIUS servers, but can also be integrated with customer RADIUS servers for additional control. Subscription based service is delivered from the Google Cloud. Regional service endpoints are added based on demand. Radiator Auth.Fi is designed to work with RADIUS roaming federations such as eduroam and govroam. Optional add-ons include client certificate authentication and self-service guest access solution and roaming federation integrations.
  • 11. Radiator Auth.Fi for… Employees, contractors, regular users of organisation Wi-Fi Organisation’s guest Wi-Fi users Roaming users
  • 14. Roaming with Radiator Auth.Fi Roaming was done bases on the Wi-Fi network name (SSID, e.g. roam.fi, eduroam)
  • 15. OpenRoaming Roaming with Radiator Auth.Fi Inbound RadSec Radiator instance with Kyrio certificates was added for IdP functionality Roam.fi federation top-level Outbound RadSec Radiator instance was used for OpenRoaming connection Providing a Radiator Auth.Fi customer OpenRoaming IdP only requires enabling it in the service and adding NAPTR record to customer DNS domain. “Available now”, only minor RADIUS attribute and Kyrio certificate CRL and 3gppnetwork.org realm configuration pending.
  • 16. How long did it take? ● ~22.5h in work time so far for both IdP and roaming service, but more as calendar time ● Configuration guides helped a lot and a guide is under work for Radiator as well => next deployment will require less work time ● Most of the calendar time was spent in waiting for Radiator Software to get verified by Kyrio and the delivery of certificates needed.
  • 17. Thank you. Questions, Comments? Follow Radiator Software for more information… Radiator Software blog: https://blog.radiatorsoftware.com/ Twitter: https://twitter.com/RadiatorAAA Slideshare: https://slideshare.net/radiatorsoftware/ Bookings for conference calls: https://radiatorsoftware.com/contact/ / info@radiatorsoftware.com
  • 18. Meet us in London 7th - 9th of November 2022 Karri Huhtanen and Heikki Vatiainen will be attending IETF 115 in London, UK on the 7th of November, but we stay in London for additional days to meet new, existing and interested customers, partners and companies. Please, contact us if you want to meet: firstname.surname@radiatorsoftware.com sales@radiatorsoftware.com